The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
|
History
21 Nov 2024, 04:54
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00033.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/23N76M3EDP2GIW4GOIQRYTKRE7PPBRB2/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTFUD5VH2GU3YOXA2KBQSBIDZRDWNZ3/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU5JJGENOK7K4X5RYAA5PL647C6HD22E/ - | |
References | () https://security.gentoo.org/glsa/202006-04 - Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20200327-0003/ - Third Party Advisory | |
References | () https://sourceware.org/bugzilla/show_bug.cgi?id=25487 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=9333498794cde1d5cca518badf79533a24114b6f - | |
References | () https://usn.ubuntu.com/4416-1/ - Third Party Advisory |
07 Nov 2023, 03:14
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-03-04 15:15
Updated : 2024-11-21 04:54
NVD link : CVE-2020-10029
Mitre link : CVE-2020-10029
CVE.ORG link : CVE-2020-10029
JSON object : View
Products Affected
netapp
- cloud_backup
- active_iq_unified_manager
- hci_management_node
- h410c_firmware
- solidfire
- steelstore_cloud_integrated_storage
- h410c
opensuse
- leap
debian
- debian_linux
canonical
- ubuntu_linux
fedoraproject
- fedora
gnu
- glibc
CWE
CWE-787
Out-of-bounds Write