peter bassill · operator
$ cve CVE-2018-6485 JSON

CVE-2018-6485

9.8
CRITICAL · CVSS 3.0 · EPSS 4.7% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.69% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2018-02-01
Last modified2026-06-17

Affected (15)

VendorProduct
gnuglibc
netappcloud backup
netappdata ontap edge
netappelement software
netappelement software management
netappsteelstore cloud integrated storage
netappstorage replication adapter
netappvasa provider
netappvirtual storage console
oraclecommunications session border controller
oracleenterprise communications broker
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
redhatvirtualization host

References

→ the Explorer  ·  watch your stack  ·  NVD