---
cve: "CVE-2020-10029"
severity: "MEDIUM"
cvss: 5.5
epss: "6.4%"
vendor: "Generic Security"
kev: false
exploited: false
published: "2020-03-04 15:15:13"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T22:55:22+02:00"
---

# CVE-2020-10029

> 5.5 MEDIUM

## Beschreibung

The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- 3de512be7ea6053255afed6154db9ee31d4e557a (Commit)

## Referenzen

- <http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00033.html>
- <https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/23N76M3EDP2GIW4GOIQRYTKRE7PPBRB2/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZTFUD5VH2GU3YOXA2KBQSBIDZRDWNZ3/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU5JJGENOK7K4X5RYAA5PL647C6HD22E/>
- <https://security.gentoo.org/glsa/202006-04>
- <https://security.netapp.com/advisory/ntap-20200327-0003/>
- <https://sourceware.org/bugzilla/show_bug.cgi?id=25487>
- <https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Ba=commit%3Bh=9333498794cde1d5cca518badf79533a24114b6f>
- <https://usn.ubuntu.com/4416-1/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2020-10029) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
