CVE detail
CVE-2019-19126 — CVE-2019-19126
Published 2019-11-19 · Modified 2026-06-17 · Vendor gnu · Product glibc · Source nvd
LOW
severity
CVSS-derived band
0.0041
EPSS probability
exploitation probability, 30d
34.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References