gnu gcc CVE-2018-12886 is a vulnerability in GNU Gcc
Published on May 22, 2019

stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.

NVD


Products Associated with CVE-2018-12886

Want to know whenever a new CVE is published for GNU Gcc? stack.watch will email you.

 

Exploit Probability

EPSS
0.17%
Percentile
38.21%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.