MEDIUM
glibc: memcmp function incorrectly returns zero
Published Feb 3, 2019
5.5
MEDIUMCVSS 3.0
EPSS 0.61%
Description
In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
glibc
Not affected
Red Hat Enterprise Linux 6
glibc
Not affected
Red Hat Enterprise Linux 7
glibc
Not affected
Red Hat Enterprise Linux 8
glibc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 7 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 8 | glibc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue only affects x32 arch, which is not supported in Red Hat Enterprise Linux kernels (CONFIG_X86_X32 is not set). Therefore glibc packages shipped with Red Hat Enterprise Linux are not affected.
Weaknesses (1)
References (8)
- http://www.securityfocus.com/bid/106835 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-7309 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1672232 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-7309
- https://security.gentoo.org/glsa/202006-04 vendor-advisoryx_refsource_GENTOO
- https://sourceware.org/bugzilla/show_bug.cgi?id=24155 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://sourceware.org/ml/libc-alpha/2019-02/msg00041.html x_refsource_MISCMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-7309
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106835 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2019-7309 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1672232 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-7309 | ||
| https://security.gentoo.org/glsa/202006-04 | vendor-advisoryx_refsource_GENTOO | |
| https://sourceware.org/bugzilla/show_bug.cgi?id=24155 | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://sourceware.org/ml/libc-alpha/2019-02/msg00041.html | x_refsource_MISCMailing ListThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-7309 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 3, 2019
Updated Aug 4, 2024
Reserved Feb 2, 2019
Link CVE-2019-7309
CISA Vulnrichment
Updated n/a