CVE-2018-6485 describes an integer overflow vulnerability in the GNU C Library (glibc) versions 2.26 and earlier, specifically within the posix_memalign and memalign functions. This flaw can lead to the allocation of an undersized heap area, potentially resulting in heap corruption across various products including GNU, NetApp, Oracle, and Red Hat. Rated as Critical with a CVSS score of 9.8, this vulnerability is easily exploitable over the network with low attack complexity, posing a significant risk of complete compromise to confidentiality, integrity, and availability. The high FAUCET Risk Score of 93/100 further emphasizes its severe impact. While there is no evidence of active exploitation (KEV: No) and no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered substantial community discussion with 10 mentions, indicating notable attention despite a lack of media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.26CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.