Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 760333 (CVE-2020-16042) - [Tracker] Operations on a BigInt could have caused uninitialized memory to be exposed (CVE-2020-16042)
Summary: [Tracker] Operations on a BigInt could have caused uninitialized memory to be...
Status: RESOLVED FIXED
Alias: CVE-2020-16042
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords: Tracker
Depends on: CVE-2020-16037, CVE-2020-16038, CVE-2020-16039, CVE-2020-16040, CVE-2020-16041 CVE-2020-26971, CVE-2020-26973, CVE-2020-26974, CVE-2020-26978, CVE-2020-35111, CVE-2020-35113, MFSA-2020-55
Blocks:
  Show dependency tree
 
Reported: 2020-12-16 18:42 UTC by Thomas Deutschmann (RETIRED)
Modified: 2020-12-23 21:30 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2020-12-16 18:42:16 UTC
When a BigInt was right-shifted the backing store was not properly cleared, allowing uninitialized memory to be read.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2020-12-23 21:30:50 UTC
No dependencies left.