glibc: stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern
Published Dec 5, 2020
7.5
HIGHCVSS 3.1
EPSS 2.72%
Description
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to sprintf. NOTE: the issue does not affect glibc by default in 2016 or later (i.e., 2.23 or later) because of commits made in 2015 for inlining of C99 math functions through use of GCC built-ins. In other words, the reference to 2.23 is intentional despite the mention of "Fixed for glibc 2.33" in the 26649 reference.
Affected products
No data.
Configuration 2
- 7.0
Configuration 3
- n/a
- n/a
No data.
Red Hat Enterprise Linux 7
glibc-0:2.17-322.el7_9
Fixed · RHSA-2021:0348
Red Hat Enterprise Linux 7.4 Advanced Update Support
glibc-0:2.17-196.el7_4.4
Fixed · RHSA-2021:2813
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
glibc-0:2.17-196.el7_4.4
Fixed · RHSA-2021:2813
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
glibc-0:2.17-196.el7_4.4
Fixed · RHSA-2021:2813
Red Hat Enterprise Linux 7.6 Advanced Update Support
glibc-0:2.17-260.el7_6.9
Fixed · RHSA-2021:3315
Red Hat Enterprise Linux 7.6 Telco Extended Update Support
glibc-0:2.17-260.el7_6.9
Fixed · RHSA-2021:3315
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
glibc-0:2.17-260.el7_6.9
Fixed · RHSA-2021:3315
Red Hat Enterprise Linux 7.7 Extended Update Support
glibc-0:2.17-292.el7_7.2
Fixed · RHSA-2021:2998
Red Hat OpenShift Do
openshiftdo/odo-init-image-rhel7:1.1.3-2
Fixed · RHSA-2021:0949
Red Hat Enterprise Linux 5
glibc
Out of support scope
Red Hat Enterprise Linux 6
glibc
Out of support scope
Red Hat Enterprise Linux 8
glibc
Not affected
Red Hat Enterprise Linux 9
glibc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | glibc-0:2.17-322.el7_9 | Fixed | RHSA-2021:0348 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | glibc-0:2.17-196.el7_4.4 | Fixed | RHSA-2021:2813 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | glibc-0:2.17-196.el7_4.4 | Fixed | RHSA-2021:2813 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | glibc-0:2.17-196.el7_4.4 | Fixed | RHSA-2021:2813 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | glibc-0:2.17-260.el7_6.9 | Fixed | RHSA-2021:3315 |
| Red Hat Enterprise Linux 7.6 Telco Extended Update Support | glibc-0:2.17-260.el7_6.9 | Fixed | RHSA-2021:3315 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | glibc-0:2.17-260.el7_6.9 | Fixed | RHSA-2021:3315 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | glibc-0:2.17-292.el7_7.2 | Fixed | RHSA-2021:2998 |
| Red Hat OpenShift Do | openshiftdo/odo-init-image-rhel7:1.1.3-2 | Fixed | RHSA-2021:0949 |
| Red Hat Enterprise Linux 5 | glibc | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | glibc | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 9 | glibc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is essentially a crash which can only be triggered by a non-standard argument passed as a long double input to a member of printf family of functions. The application has to be written in this way to allow this issue to be triggered. The maximum impact is an application crash.
References (9)
- https://access.redhat.com/security/cve/CVE-2020-29573 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1905213 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21935 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-29573
- https://security.gentoo.org/glsa/202101-20 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210122-0004/ x_refsource_CONFIRMThird Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=26649 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://sourceware.org/pipermail/libc-alpha/2020-September/117779.html x_refsource_MISCPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-29573
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-29573 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1905213 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21935 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-29573 | ||
| https://security.gentoo.org/glsa/202101-20 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://security.netapp.com/advisory/ntap-20210122-0004/ | x_refsource_CONFIRMThird Party Advisory | |
| https://sourceware.org/bugzilla/show_bug.cgi?id=26649 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://sourceware.org/pipermail/libc-alpha/2020-September/117779.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-29573 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data