[glibc] Don't write beyond destination in __mempcpy_avx512_no_vzeroupper

Bug #1776124 reported by quanxian
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
intel
Fix Released
Medium
Unassigned
Ubuntu
Fix Released
Undecided
Unassigned

Bug Description

Description:
a corner case with glibc code that causes KNL/KNM system hang.

"
Don't write beyond destination in __mempcpy_avx512_no_vzeroupper (bug 23196)

When compiled as mempcpy, the return value is the end of the destination
buffer, thus it cannot be used to refer to the start of it.
"

Here is the commit for this issue.

https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commit;h=9aaaab7c6e4176e61c59b0a63c6ba906d875dc0e

18.04 and 19.04 need backport this patch into glibc.

Details:
For details, please refer to:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-11237
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-11237.html
https://sourceware.org/bugzilla/show_bug.cgi?id=23196

Target Package: glibc
Target Release: 18.04.x/18.10

quanxian (quanxian-wang)
description: updated
tags: added: intel-upkg-18.10
tags: added: intel-upkg-18.04
description: updated
Revision history for this message
Joseph Salisbury (jsalisbury) wrote :

Can we move this bug to the "Linux" package and make it public?

Changed in intel:
importance: Undecided → Medium
status: New → Triaged
tags: added: kernel-da-key
Revision history for this message
quanxian (quanxian-wang) wrote :

yes, please.

quanxian (quanxian-wang)
information type: Proprietary → Public
quanxian (quanxian-wang)
tags: added: intel-upkg-19.04
removed: intel-upkg-18.10
description: updated
Revision history for this message
quanxian (quanxian-wang) wrote :

2.29 is included in 19.04

Changed in ubuntu:
status: New → Fix Released
Changed in intel:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.