Impact
The flaw arises in the GNU C Library's tdelete routine. When a tree with sufficient depth is deleted, the rebalancing code uses an alloca-allocated array as a stack of parent nodes. Two branches of the algorithm push an additional element onto this array without first checking its capacity. If the array is already full—which occurs when the tree has a depth of exactly 40 (or 40 plus multiples of 20)—the code writes one pointer past the end of the buffer. The overwritten value is a pointer to a tree node that is not directly controllable by an attacker, and the out-of-bounds write corrupts the stack, causing the application to crash. The vulnerability requires an attacker to drive a large number of insertions and deletions through an application using tsearch and tdelete to create a tree of the required depth, which makes exploitation nontrivial and likely limited to local or unprivileged users interacting with the application. The weakness is a stack-based buffer overflow classified as CWE-121 and CWE-787; its impact is primarily disruption of application availability.
Affected Systems
The vulnerability impacts the GNU C Library (glibc), a core component of Linux systems. It affects glibc versions 2.1 through 2.44, which includes many distribution releases. The advisory does not list a particular distribution or patch version, but any system running a vulnerable glibc build is potentially impacted.
Risk and Exploitability
With a CVSS score of 5.6 the severity is moderate. Exploitation requires the attacker to drive a large number of insertions and deletions through an application that uses tsearch and tdelete, and the flaw may crash the application. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been witnessed in widespread deployment reports as of the last update.
OpenCVE Enrichment
Ubuntu USN