First published: Wed Mar 04 2020(Updated: )
GNU C Library (aka glibc or libc6) is vulnerable to a denial of service, caused by a stack-based overflow during range reduction. A local attacker could exploit this vulnerability to cause a stack corruption, leading to a denial of service condition.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library (glibc) | <2.32.0 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =18.04 | |
Ubuntu Linux | =19.10 | |
openSUSE | =15.1 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp cloud backup | ||
netapp hci management node | ||
netapp solidfire | ||
NetApp SteelStore | ||
All of | ||
netapp h410c firmware | ||
netapp h410c | ||
Debian GNU/Linux | =10.0 | |
IBM Cloud Pak for Security | <=1.6.0.1 | |
IBM Cloud Pak for Security | <=1.6.0.0 | |
IBM Cloud Pak for Security | <=1.5.0.1 | |
IBM Cloud Pak for Security | <=1.5.0.0 | |
IBM Cloud Pak for Security | <=1.4.0.0 | |
debian/glibc | 2.31-13+deb11u11 2.31-13+deb11u10 2.36-9+deb12u9 2.36-9+deb12u7 2.40-7 | |
GNU C Library | <2.32.0 | |
Fedora | =30 | |
Fedora | =31 | |
Fedora | =32 | |
SUSE openSUSE | =15.1 | |
NetApp Cloud Backup | ||
NetApp HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp SteelStore Cloud Integrated Storage | ||
NetApp H410C Firmware | ||
NetApp H410C | ||
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10029 is a vulnerability in the GNU C Library (glibc) that could cause a denial of service by overflowing an on-stack buffer.
The severity of CVE-2020-10029 is medium, with a severity value of 5.5.
The affected software versions are glibc 2.27-3ubuntu1.2, glibc 2.30, glibc 2.23-0ubuntu11.2, and various versions of glibc from Debian and IBM Cloud Pak for Security.
To fix CVE-2020-10029, upgrade to the recommended versions of glibc provided by the respective vendors or distribution maintainers.
You can find more information about CVE-2020-10029 on the CVE Mitre website, Ubuntu Security Notices, and NIST National Vulnerability Database.