PT-2019-6228 · Gnu+6 · Gnu C Library+6

Marcin Kościelnicki

·

Published

2019-11-19

·

Updated

2024-06-15

·

CVE-2019-19126

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNU C Library versions prior to 2.31
Description The issue is related to the incorrect handling of the LD PREFER MAP 32BIT EXEC environment variable, which allows local attackers to restrict the possible mapping addresses for loaded libraries. This can lead to bypassing Address Space Layout Randomization (ASLR) for a setuid program, potentially giving attackers access to confidential data.
Recommendations For versions prior to 2.31, update to version 2.31 or later to resolve the issue. As a temporary workaround, consider disabling the use of the LD PREFER MAP 32BIT EXEC environment variable until a patch is available.

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3524
BDU:2022-05763
CESA-2020_1828
CESA-2020_3861
CVE-2019-19126
DLA-3152-1
MGASA-2019-0349
OPENSUSE-SU-2024:10792-1
RHSA-2020:1828
RHSA-2020:3861
RHSA-2020_1828
RHSA-2020_3861
SUSE-SU-2020:0262-1
SUSE-SU-2020_0262-1
USN-4416-1

Affected Products

Alt Linux
Astra Linux
Centos
Gnu C Library
Red Hat
Suse
Ubuntu