Logo
vulnerabilityCVE-2025-5702
Name
CVE-2025-5702
Source
NVD ( link)Debian ( link)
Description
The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
glibc
Exploitable

Vulnerability Ratings#


5.6
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.41-137-gb676adadbc1f5fb2f31bc484a7628cca89ae6f22
Not Affected
buildroot
master
2.43-27-g4070d808bea1c077eb7e7d52b52b91cae98205d5
Not Affected
yocto
kirkstone
2.35
Not Affected
yocto
master
2.43+git
Not Affected