Back

MEDIUM

glibc: memcmp function incorrectly returns zero

Published Feb 3, 2019

Description

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

Affected products

Remediation

Red Hat statement

This issue only affects x32 arch, which is not supported in Red Hat Enterprise Linux kernels (CONFIG_X86_X32 is not set). Therefore glibc packages shipped with Red Hat Enterprise Linux are not affected.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 3, 2019
Updated Aug 4, 2024
Reserved Feb 2, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 2, 2019