PT-2019-5586 · Gnu+2 · Gnu C Library+2

Hongxu Chen

·

Published

2019-02-25

·

Updated

2026-05-04

·

CVE-2018-20796

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU C Library (aka glibc or libc6) versions prior to 2.30
Description The issue is related to uncontrolled recursion in the GNU C Library when processing regular expressions. This can lead to a denial of service. The problem arises when the library attempts to match certain patterns, such as '(227|)(11|t1|2537)+', as demonstrated in the grep command.
Recommendations For GNU C Library versions prior to 2.30, update to version 2.30 or later to resolve the issue. As a temporary workaround, consider restricting the use of complex regular expressions in applications that utilize the GNU C Library until a patch is applied.

Exploit

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3114
BDU:2020-04530
CVE-2018-20796
ECHO-C300-439C-0DDA

Affected Products

Alt Linux
Debian
Gnu C Library