PT-2019-5763 · Musl+4 · Musl Libc+4

Rich Felker

·

Published

2019-08-06

·

Updated

2024-10-17

·

CVE-2019-14697

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions musl libc versions prior to 1.1.24
Description The issue is related to an x87 floating-point stack adjustment imbalance in the math/i386/ directory of the musl libc library. This imbalance can lead to out-of-bounds writes not present in an application's source code. In some cases, exploitation of this issue may allow a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations For musl libc versions prior to 1.1.24, update to version 1.1.24 or later to resolve the issue. As a temporary workaround, consider restricting the use of the math/i386/ directory functions until a patch is available.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2024-13885
BDU:2021-01480
CVE-2019-14697
OPENSUSE-SU-2024:10761-1
USN-5990-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Ubuntu
Musl Libc