CVE-2018-20542

Source
https://cve.org/CVERecord?id=CVE-2018-20542
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20542.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-20542
Downstream
Published
2018-12-28T16:29:04Z
Modified
2026-04-11T14:11:02Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

There is a heap-based buffer-overflow at generator_spgemm_csc_reader.c (function libxsmm_sparse_csc_reader) in LIBXSMM 1.10, a different vulnerability than CVE-2018-20541 (which is in a different part of the source code and is seen at a different address).

References

Affected packages

Git / github.com/hfp/libxsmm

Affected ranges

Type
GIT
Repo
https://github.com/hfp/libxsmm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/hfp/libxsmm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20542.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.10"
            }
        ]
    }
]
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "253237323125577349990588301710073922474",
            "length": 2899
        },
        "id": "CVE-2018-20542-42082ee1",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "src/generator_spgemm_csr_reader.c",
            "function": "libxsmm_sparse_csr_reader"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "257932478644569493591294152135594238066",
            "length": 2305
        },
        "id": "CVE-2018-20542-44059b59",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "samples/edge/edge_proxy_common.c",
            "function": "edge_sparse_csr_reader_double"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "241923795223860916277411171048424946468",
                "209110177833169472757848964198364002047",
                "226469009479139064176779870339992460152",
                "192626307265761018682685695128013722668",
                "261546154635701793906232853738646677101",
                "18508411805474619725990427461893891957",
                "51501535861073324594083067657348697914",
                "110807367558379506002077375399143442439",
                "257165498594075926253907697244042964172"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2018-20542-5066215b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "src/generator_spgemm_csr_reader.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "241923795223860916277411171048424946468",
                "209110177833169472757848964198364002047",
                "54720283948260693235784795782894161382",
                "159871792082033176477973504123091930777"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2018-20542-914a6527",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "samples/edge/edge_proxy_common.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "241923795223860916277411171048424946468",
                "209110177833169472757848964198364002047",
                "54720283948260693235784795782894161382",
                "217042301667030676819970089241851533120"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2018-20542-956a0ae8",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "samples/pyfr/pyfr_driver_asp_reg.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "241923795223860916277411171048424946468",
                "107558474951648408386904201689056226698",
                "283203830907550038709210239009337494119",
                "18022234622339816638805531357357536949",
                "291840242035544412416174133096187863902",
                "18508411805474619725990427461893891957",
                "4969517896670101590188015537595354571",
                "291749407274234609554627974998776176771",
                "205777411820530140292049990175321492587",
                "206743855182286230386096444765258334159"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2018-20542-a58f01b5",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "src/generator_spgemm_csc_reader.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "117423682803360476822542486759614065109",
            "length": 2899
        },
        "id": "CVE-2018-20542-d0044958",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "src/generator_spgemm_csc_reader.c",
            "function": "libxsmm_sparse_csc_reader"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "252726746632772907463537910857054546701",
            "length": 2342
        },
        "id": "CVE-2018-20542-ee91e15d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "samples/pyfr/pyfr_driver_asp_reg.c",
            "function": "my_csr_reader"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "288578049635566099234369255849468353491",
            "length": 2495
        },
        "id": "CVE-2018-20542-f3f56076",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "samples/edge/common_edge_proxy.h",
            "function": "libxsmm_sparse_csr_reader"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "241923795223860916277411171048424946468",
                "209110177833169472757848964198364002047",
                "54720283948260693235784795782894161382",
                "217042301667030676819970089241851533120"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2018-20542-ffa602e8",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/hfp/libxsmm/commit/151481489192e6d1997f8bde52c5c425ea41741d",
        "target": {
            "file": "samples/edge/common_edge_proxy.h"
        }
    }
]
vanir_signatures_modified
"2026-04-11T14:11:02Z"