PT-2020-3258 · Gnu+4 · Glibc+4

Published

2020-04-01

·

Updated

2024-06-15

·

CVE-2020-6096

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU glibc version 2.30.9000
Description An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation. Calling memcpy() with a negative value for the num parameter results in a signed comparison vulnerability, potentially leading to undefined behavior such as writing to out-of-bounds memory and remote code execution. The vulnerability allows program execution to continue in scenarios where a segmentation fault or crash should have occurred, resulting in subsequent execution with corrupted data.
Recommendations For GNU glibc version 2.30.9000, consider disabling the memcpy() function until a patch is available to prevent potential remote code execution. Restrict access to the vulnerable memcpy() implementation to minimize the risk of exploitation. Avoid using the num parameter with negative values in the affected memcpy() function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3299
ALT-PU-2020-3327
ALT-PU-2020-3401
ALT-PU-2020-3524
BDU:2020-03566
CVE-2020-6096
DLA-3152-1
MGASA-2021-0053
OPENSUSE-SU-2024:10792-1
USN-4954-1
USN-5310-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Ubuntu
Glibc