Impact
The vulnerability arises from an out‑of‑bounds array write in the glibc tdelete function, a classic buffer overflow identified as CWE‑787. If triggered, the flaw corrupts memory which can lead to a denial of service or accidental disclosure of data. The description specifically notes that local attackers with low privileges could exploit it.
Affected Systems
The flaw affects the glibc library, which is a core component of many Linux distributions. No specific versions are listed in the advisory, so any system using an affected glibc build from the listed reference URLs is potentially impacted.
Risk and Exploitability
With a CVSS score of 4.2 the severity is moderate. Exploitation conditions require a local attacker with low privileges that can invoke the tdelete routine, which normally occurs in user‑level processes. The EPSS score is not available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating it has not been witnessed in widespread deployment reports as of the last update.
OpenCVE Enrichment