musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade musl | Nov 8, 2019 | Aug 6, 2019 |
| Debian | — | Upgrade musl | Jul 30, 2024 | Aug 6, 2019 |
| Gentoo Linux | — | Upgrade sys-libs/musl. | Mar 16, 2020 | Aug 6, 2019 |
| Ubuntu | — | Upgrade musl (Ubuntu Pro)Upgrade musl-dev (Ubuntu Pro) | Apr 10, 2023 | Aug 6, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub