Executive brief
libstdc++ is a core C++ standard library used by applications to manage memory and perform computations. An integer overflow in its memory allocation function can cause the library to allocate too little memory for large requests, leading to memory corruption or crashes when the application writes to the undersized buffer.
Technical details
An integer overflow vulnerability exists in the aligned operator new function of libstdc++ when processing large allocation requests. The overflow causes undersized memory allocation, leading to out-of-bounds writes and potential memory corruption or application instability. Exploitation requires an attacker to control or influence allocation size parameters, typically requiring code execution or unsafe input handling in the calling application.
Affected products
- GNU libstdc++