Use-after-free in GNU C Library (glibc) - CVE-2020-1752

 

Use-after-free in GNU C Library (glibc) - CVE-2020-1752

Published: April 7, 2020


Vulnerability identifier: #VU26628
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1752
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the glob() function in glibc in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username are affected by this issue. A local user can create a specially crafted path that, when processed by the glob() function, would potentially lead to arbitrary code execution.


Affected software

GNU C Library (glibc)
SIMATIC S7-1500 TM MFP - BIOS
Gentoo Linux
SUSE OpenStack Cloud
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
Ubuntu
Fedora
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
glibc (Red Hat package)
glibc-locale-debuginfo
nscd-debuginfo
nscd
glibc-profile-32bit
glibc-profile
glibc-locale-debuginfo-32bit
glibc-locale-32bit
glibc-locale
glibc-devel-debuginfo-32bit
glibc-devel-debuginfo
glibc-devel
glibc-html
glibc-devel-32bit
glibc-i18ndata
glibc-info
glibc
glibc-32bit
glibc-debuginfo
glibc-debuginfo-32bit
glibc-debugsource
libc6 (Ubuntu package)
sys-libs/glibc
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Cloud Transformation Advisor
RecoverPoint for Virtual Machines
Db2 Rest
Cloud Pak for Network Automation

How to mitigate CVE-2020-1752

Install updates from vendor's website.

GNU C Library (glibc) - update to 2.31
Red Hat OpenShift Serverless - addressed in versions 1.11.0, 1.12.0
glibc (Red Hat package) - update to 2.28-127.el8
Quay - update to 3.3.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Db2 Rest - update to 1.0.0.304
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Network Automation - update to 2.6.4
glibc-locale-debuginfo - update to 2.22-123.1
nscd-debuginfo - update to 2.22-123.1
nscd - update to 2.22-123.1
glibc-profile-32bit - update to 2.22-123.1
glibc-profile - update to 2.22-123.1
glibc-locale-debuginfo-32bit - update to 2.22-123.1
glibc-locale-32bit - update to 2.22-123.1
glibc-locale - update to 2.22-123.1
glibc-devel-debuginfo-32bit - update to 2.22-123.1
glibc-devel-debuginfo - update to 2.22-123.1
glibc-devel - update to 2.22-123.1
glibc-html - update to 2.22-123.1
glibc-devel-32bit - update to 2.22-123.1
glibc-i18ndata - update to 2.22-123.1
glibc-info - update to 2.22-123.1
glibc - update to 2.22-123.1
glibc-32bit - update to 2.22-123.1
glibc-debuginfo - update to 2.22-123.1
glibc-debuginfo-32bit - update to 2.22-123.1
glibc-debugsource - update to 2.22-123.1
libc6 (Ubuntu package) - addressed in versions 2.23-0ubuntu11.2, 2.27-3ubuntu1.2, 2.30-0ubuntu2.2
glibc - addressed in versions 2.29-29.fc30, 2.30-11.fc31, 2.31-2.fc32
sys-libs/glibc - update to 2.32-r5
IBM Cloud Transformation Advisor - update to 3.10.0

External References

Related Security Bulletins