CVE-2018-6485

An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
gnuglibc
𝑥
≤ 2.26
redhatvirtualization_host
4.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_workstation
7.0
oraclecommunications_session_border_controller
8.0.0
oraclecommunications_session_border_controller
8.1.0
oraclecommunications_session_border_controller
8.2.0
oracleenterprise_communications_broker
3.0.0
oracleenterprise_communications_broker
3.1.0
netappcloud_backup
-
netappdata_ontap_edge
-
netappelement_software
-
netappelement_software_management
-
netappsteelstore_cloud_integrated_storage
-
netappstorage_replication_adapter
7.2 ≤
netappvasa_provider
7.2 ≤
netappvasa_provider
6.x:x
netappvirtual_storage_console
7.2 ≤
netappvirtual_storage_console
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
glibc
bullseye
2.31-13+deb11u11
fixed
wheezy
ignored
bullseye (security)
2.31-13+deb11u10
fixed
bookworm
2.36-9+deb12u8
fixed
bookworm (security)
2.36-9+deb12u7
fixed
sid
2.40-3
fixed
trixie
2.40-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
eglibc
focal
dne
eoan
dne
disco
dne
cosmic
dne
bionic
dne
artful
dne
xenial
dne
trusty
Fixed 2.19-0ubuntu6.15+esm1
released
glibc
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
ignored
xenial
Fixed 2.23-0ubuntu11.2
released
trusty
dne