The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade eglibcUpgrade glibc | Jul 30, 2024 | Oct 4, 2013 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Oct 4, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 15, 2013 |
| Suse | — | Upgrade glibc-locale-x86Upgrade glibc-32bitUpgrade glibc-infoUpgrade glibc-i18ndataUpgrade glibc-profileUpgrade glibc-develUpgrade glibc-x86Upgrade glibc-localeUpgrade glibcUpgrade sle-sdk-releaseUpgrade glibc-profile-x86Upgrade glibc-locale-32bitUpgrade nscdUpgrade glibc-profile-32bitUpgrade glibc-htmlUpgrade glibc-devel-32bit | Dec 12, 2013 | Oct 4, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub