Information disclosure in GNU C Library (glibc) - CVE-2019-19126

 

Information disclosure in GNU C Library (glibc) - CVE-2019-19126

Published: November 19, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30596
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19126
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.


Affected software

GNU C Library (glibc)
Amazon Linux AMI
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Ubuntu
Fedora
glibc (Red Hat package)
libc6 (Ubuntu package)
glibc
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Ansible Automation Platform
Netcool Operations Insight
IBM Cloud Transformation Advisor
RecoverPoint for Virtual Machines
Db2 Rest
Cloud Pak for Network Automation
Red Hat OpenShift Container Platform

How to mitigate CVE-2019-19126

Install update from vendor's website.

GNU C Library (glibc) - update to 2.31
glibc (Red Hat package) - addressed in versions 2.17-317.el7, 2.28-101.el8
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - addressed in versions 4.5.3, 4.8.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Ansible Automation Platform - addressed in versions 1.0, 1.1
Db2 Rest - update to 1.0.0.304
Netcool Operations Insight - update to 1.6.8
Cloud Pak for Network Automation - update to 2.6.4
libc6 (Ubuntu package) - addressed in versions 2.23-0ubuntu11.2, 2.27-3ubuntu1.2, 2.30-0ubuntu2.2
glibc - addressed in versions 2.29-28.fc30, 2.30-10.fc31
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Container Platform - update to 4.3.40

External References

Related Security Bulletins