First published: Wed Jan 22 2025(Updated: )
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Affected Software | Affected Version | How to fix |
---|---|---|
GNU C Library | >=2.13<=2.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2339460 is considered critical due to the potential for a buffer overflow.
To fix REDHAT-BUG-2339460, upgrade the GNU C Library to a version later than 2.40.
Versions 2.13 to 2.40 of the GNU C Library are affected by REDHAT-BUG-2339460.
REDHAT-BUG-2339460 causes a buffer overflow due to insufficient space allocation for assertion failure messages.
As of now, there are no known exploits directly associated with REDHAT-BUG-2339460, but the vulnerability poses a significant risk.