← Back to CVE List

CVE-2018-12886

Published: 2019-05-22T19:29Z
Last Modified: 2024-11-21T03:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt