FlawAtlas
Search the atlas
SUSE-SU-2021:0653-1 Not scored

Security update for glibc

This update for glibc fixes the following issues: - Fix buffer overrun in EUC-KR conversion module (CVE-2019-25013, bsc#1182117, BZ #24973) - x86: Harden printf against non-normal long double values (CVE-2020-29573, bsc#1179721, BZ #26649) - gconv: Fix assertion failure in ISO-2022-JP-3 module (CVE-2021-3326, bsc#1181505, BZ #27256) - iconv: Accept redundant shift sequences in IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224) - iconv: Fix incorrect UCS4 inner loop bounds (CVE-2020-29562, bsc#1179694, BZ #26923) - Fix parsing of /sys/devices/system/cpu/online (bsc#1180038, BZ #25859)

Exploit probability Not scored
Published February 26, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise High Performance Computing 15-ESPOS glibc
SUSE:Enterprise Storage 6 glibc
SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS glibc
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS glibc
SUSE:Linux Enterprise High Performance Computing 15-LTSS glibc
SUSE:Linux Enterprise Module for Basesystem 15 SP2 glibc
SUSE:Linux Enterprise Module for Development Tools 15 SP2 glibc
SUSE:Linux Enterprise Server 15 SP1-BCL glibc
SUSE:Linux Enterprise Server 15 SP1-LTSS glibc
SUSE:Linux Enterprise Server 15-LTSS glibc
SUSE:Linux Enterprise Server for SAP Applications 15 glibc
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 glibc
SUSE:Manager Proxy 4.0 glibc
SUSE:Manager Retail Branch Server 4.0 glibc
SUSE:Manager Server 4.0 glibc

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:0653-1

This update for glibc fixes the following issues: - Fix buffer overrun in EUC-KR conversion module (CVE-2019-25013, bsc#1182117, BZ #24973) - x86: Harden printf against non-normal long double values (CVE-2020-29573, bsc#1179721, BZ #26649) - gconv: Fix assertion failure in ISO-2022-JP-3 module (CVE-2021-3326, bsc#1181505, BZ #27256) - iconv: Accept redundant shift sequences in IBM1364 (CVE-2020-27618, bsc#1178386, BZ #26224) - iconv: Fix incorrect UCS4 inner loop bounds (CVE-2020-29562, bsc#1179694, BZ #26923) - Fix parsing of /sys/devices/system/cpu/online (bsc#1180038, BZ #25859)

View original source

05 / REFERENCES

Further evidence