CVE-2019-7309 PUBLISHED

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

EPSS 0.17% · 37.5th percentile

Risk Scores

EPSS Score
0.17%
37.5th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSglibc0, 2.27-3ubuntu1.6+esm6, 2.27-3ubuntu1.6+esm5
Ubuntu:Pro:16.04:LTSglibc2.23-0ubuntu11, 0, 2.21-0ubuntu4
Ubuntu:Pro:14.04:LTSeglibc2.19-0ubuntu6, 2.19-0ubuntu5, 0

Timeline

References

Open in Interactive Console →