First published: Thu Feb 01 2018(Updated: )
A flaw was found in glibc. An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption. References: <a href="https://sourceware.org/bugzilla/show_bug.cgi?id=22343">https://sourceware.org/bugzilla/show_bug.cgi?id=22343</a> Patch: <a href="https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=8e448310d74b283c5cd02b9ed7fb997b47bf9b22">https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=8e448310d74b283c5cd02b9ed7fb997b47bf9b22</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU glibc | <=2.26 | |
Redhat Virtualization Host | =4.0 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
Oracle Communications Session Border Controller | =8.0.0 | |
Oracle Communications Session Border Controller | =8.1.0 | |
Oracle Communications Session Border Controller | =8.2.0 | |
Oracle Enterprise Communications Broker | =3.0.0 | |
Oracle Enterprise Communications Broker | =3.1.0 | |
Netapp Cloud Backup | ||
Netapp Data Ontap Edge | ||
Netapp Element Software | ||
Netapp Element Software Management | ||
Netapp Steelstore Cloud Integrated Storage | ||
Netapp Storage Replication Adapter | >=7.2 | |
Netapp Vasa Provider Clustered Data Ontap | >=7.2 | |
Netapp Vasa Provider Clustered Data Ontap | =6.x | |
Netapp Virtual Storage Console Vmware Vsphere | >=7.2 | |
Netapp Virtual Storage Console | ||
debian/glibc | 2.31-13+deb11u11 2.31-13+deb11u10 2.36-9+deb12u9 2.36-9+deb12u7 2.40-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6485 is an integer overflow vulnerability in the GNU C Library (glibc) that could potentially lead to heap corruption.
CVE-2018-6485 has a severity rating of 9.8, which is considered critical.
Versions 2.26 and earlier of the GNU C Library (glibc) are affected by CVE-2018-6485.
To remedy CVE-2018-6485, update to version 2.28-10+deb10u1 or later for Debian, or 2.19-0ubuntu6.15+ for Ubuntu.
You can find more information about CVE-2018-6485 in the Debian bug report, the Sourceware bugzilla, and the SecurityFocus vulnerability database.