mirror of
https://sourceware.org/git/glibc.git
synced 2024-11-09 23:00:07 +00:00
Update NEWS for CVE-2019-19126
This commit is contained in:
parent
2626b15e88
commit
5422ac2d08
6
NEWS
6
NEWS
@ -51,6 +51,12 @@ Security related changes:
|
||||
via proceed_next_node in posix/regexec.c leads to heap-based buffer
|
||||
over-read. Reported by Hongxu Chen.
|
||||
|
||||
CVE-2019-19126: ld.so failed to ignore the LD_PREFER_MAP_32BIT_EXEC
|
||||
environment variable during program execution after a security
|
||||
transition, allowing local attackers to restrict the possible mapping
|
||||
addresses for loaded libraries and thus bypass ASLR for a setuid
|
||||
program. Reported by Marcin Kościelnicki.
|
||||
|
||||
|
||||
Version 2.29
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user