Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-5702

Опубликовано: 05 июн. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 5.6

Описание

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

pending

2.41-9ubuntu1
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

released

2.39-0ubuntu8.5
oracular

ignored

end of life, was needed
plucky

released

2.41-6ubuntu1.1
upstream

needs-triage

Показывать по

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
redhat
2 месяца назад

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.

CVSS3: 5.6
nvd
2 месяца назад

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.

CVSS3: 5.6
debian
2 месяца назад

The strcmp implementation optimized for the Power10 processor in the G ...

CVSS3: 5.6
github
2 месяца назад

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.

oracle-oval
около 1 месяца назад

ELSA-2025-9877: glibc security update (MODERATE)

5.6 Medium

CVSS3