CVE-2019-9192: High severity GNU glibc vulnerability
DISPUTED In the GNU C Library (aka glibc or libc6) through 2.29, checkdstlimitscalcpos1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.28-24
Event History
Frequently Asked Questions
What is CVE-2019-9192?
CVE-2019-9192 is a vulnerability in the GNU C Library (glibc) that allows for uncontrolled recursion.
How severe is CVE-2019-9192?
CVE-2019-9192 has a severity score of 7.5 (high).
How does CVE-2019-9192 affect GNU C Library (glibc)?
CVE-2019-9192 affects GNU C Library (glibc) versions up to 2.29.
What is the impact of CVE-2019-9192?
CVE-2019-9192 allows attackers to cause a denial of service or potentially execute arbitrary code.
Is there a fix for CVE-2019-9192?
As of now, there is no official fix or patch available for CVE-2019-9192. It is recommended to keep systems up to date with the latest security patches and monitor for any vendor updates.