FlawAtlas
Search the atlas
CVE-2019-7309 Moderate

CVE-2019-7309

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

Exploit probability 0.6%
Published February 3, 2019
Required by Not available
Last source change August 19, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

1213 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-7309

In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.

View original source

05 / REFERENCES

Further evidence