USN-4954-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 14 May 2021, 00:19
Last modified:27 Apr 2026, 19:02

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 May 2021, 00:19
Published
Vulnerability first disclosed
27 Apr 2026, 19:02
Last Modified
Vulnerability information updated

Description

glibc vulnerabilities Jason Royes and Samuel Dytrych discovered that the memcpy() implementation for 32 bit ARM processors in the GNU C Library contained an integer underflow vulnerability. An attacker could possibly use this to cause a denial of service (application crash) or execute arbitrary code. (CVE-2020-6096) It was discovered that the POSIX regex implementation in the GNU C Library did not properly parse alternatives. An attacker could use this to cause a denial of service. (CVE-2009-5155)

Affected Systems

  • ubuntuglibc

    < 2.23-0ubuntu11.3

References (3)