CVE-2018-11237: Buffer Overflow
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in mempcpyavx512novzeroupper.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/glibcto a version that resolves this vulnerability.Fixed in 2.28 - Upgrade
Upgrade
debian/glibcto a version that resolves this vulnerability.Fixed in 2.31-13+deb11u11Fixed in 2.31-13+deb11u14Fixed in 2.36-9+deb12u14Fixed in 2.36-9+deb12u7Fixed in 2.41-12+deb13u3Fixed in 2.42-17 - Upgrade
Upgrade
GNU C Library (glibc/libc6)to a version that resolves this vulnerability.Fixed in 2.27 and earlier - Compensating control
Mitigate the potential buffer overflow by applying the upstream/downstream fix referenced by sourceware bug 23196 and Red Hat bug 1579809 for GNU C Library (glibc/libc6) AVX-512 mempcpy __mempcpy_avx512_no_vzeroupper.
Event History
Frequently Asked Questions
What is CVE-2018-11237?
CVE-2018-11237 is a vulnerability in the GNU C Library (glibc) that allows for a buffer overflow, potentially leading to remote code execution.
What is the severity of CVE-2018-11237?
CVE-2018-11237 has a severity score of 7.8, which is considered high.
Which software versions are affected by CVE-2018-11237?
The GNU C Library (glibc) versions 2.27 and earlier are affected by CVE-2018-11237.
How can I fix CVE-2018-11237?
To fix CVE-2018-11237, you should update glibc to version 2.28 or later.
Where can I find more information about CVE-2018-11237?
You can find more information about CVE-2018-11237 on the official Red Hat Bugzilla page (https://sourceware.org/bugzilla/show_bug.cgi?id=23196) and the SecurityFocus page (http://www.securityfocus.com/bid/104256).