CVE-2019-19126: Low severity GNU glibc vulnerability
Last updated 25 August 2025
Other sources
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LDPREFERMAP32BITEXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/glibcto a version that resolves this vulnerability.Fixed in 2.31-13+deb11u11Fixed in 2.31-13+deb11u14Fixed in 2.36-9+deb12u14Fixed in 2.36-9+deb12u7Fixed in 2.41-12+deb13u3Fixed in 2.42-17 - Upgrade
Upgrade
glibcto a version that resolves this vulnerability.Fixed in 2.31 - Compensating control
Ensure untrusted local users cannot influence execution environment variables (e.g., LD_PREFER_MAP_32BIT_EXEC) for a setuid program, since glibc < 2.31 may fail to ignore LD_PREFER_MAP_32BIT_EXEC after a security transition.
Event History
Frequently Asked Questions
What is CVE-2019-19126?
CVE-2019-19126 is a vulnerability in the GNU C Library (glibc) that allows local attackers to restrict the possible mapping addresses for loaded libraries and bypass ASLR.
How does CVE-2019-19126 impact the x86-64 architecture?
CVE-2019-19126 affects the x86-64 architecture by failing to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution.
Which versions of glibc are affected by CVE-2019-19126?
Versions 2.28-10+deb10u2, 2.31-13+deb11u6, 2.31-13+deb11u7, 2.36-9+deb12u2, 2.36-9+deb12u3, and 2.37-12 of glibc are affected by CVE-2019-19126.
How can local attackers exploit CVE-2019-19126?
Local attackers can exploit CVE-2019-19126 by using the LD_PREFER_MAP_32BIT_EXEC environment variable to restrict the possible mapping addresses for loaded libraries.
What is the severity of CVE-2019-19126?
CVE-2019-19126 has a severity rating of low with a score of 3.3.