CVE-2019-19126: Canonical Ubuntu Linux
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- GNU Glibc: before 2.31 (fixed in 2.31)
Published 2019-11-19. Last modified 2026-06-17.