Out-of-bounds write in GNU C Library (glibc) - CVE-2020-1751
Published: April 20, 2020
Vulnerability identifier: #VU27033
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1751
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error in the "backtrace" function when handling signal trampolines on PowerPC. A remote attacker can trigger out-of-bounds write and execute arbitrary code on the target system.
Affected software
GNU C Library (glibc)
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Fedora
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
glibc (Red Hat package)
libc6 (Ubuntu package)
glibc
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Cloud Transformation Advisor
Db2 Rest
Cloud Pak for Network Automation
Cloud Pak for Data
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
Fedora
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
glibc (Red Hat package)
libc6 (Ubuntu package)
glibc
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Cloud Transformation Advisor
Db2 Rest
Cloud Pak for Network Automation
Cloud Pak for Data
How to mitigate CVE-2020-1751
Install updates from vendor's website.
GNU C Library (glibc) - update to 2.31
Red Hat OpenShift Serverless - addressed in versions 1.11.0, 1.12.0
glibc (Red Hat package) - update to 2.28-127.el8
Quay - update to 3.3.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
Db2 Rest - update to 1.0.0.304
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Network Automation - update to 2.6.4
libc6 (Ubuntu package) - addressed in versions 2.23-0ubuntu11.2, 2.27-3ubuntu1.2, 2.30-0ubuntu2.2
glibc - addressed in versions 2.29-29.fc30, 2.30-11.fc31
Cloud Pak for Data - update to 3.0.1 lite patch 7
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Serverless - addressed in versions 1.11.0, 1.12.0
glibc (Red Hat package) - update to 2.28-127.el8
Quay - update to 3.3.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
Db2 Rest - update to 1.0.0.304
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Network Automation - update to 2.6.4
libc6 (Ubuntu package) - addressed in versions 2.23-0ubuntu11.2, 2.27-3ubuntu1.2, 2.30-0ubuntu2.2
glibc - addressed in versions 2.29-29.fc30, 2.30-11.fc31
Cloud Pak for Data - update to 3.0.1 lite patch 7
IBM Cloud Transformation Advisor - update to 3.10.0
External References
Related Security Bulletins
- Multiple vulnerabilities in glibc
- Gentoo update for glibc
- Red Hat Enterprise Linux 8 update for glibc
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Out-of-bounds write in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Out-of-bounds write in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM Db2 Rest
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Ubuntu update for glibc
- Fedora 30 update for glibc
- Fedora 31 update for glibc