It was found that a memory leak can be reached and amplified through the LD_HWCAP_MASK environment variable. It's not exploitable if the glibc is patched against CVE-2017-1000366, because this patch ignores the LD_HWCAP_MASK and LD_LIBRARY_PATH environment variables when SUID binaries are executed Introducing commit: https://sourceware.org/git/gitweb.cgi?p=glibc.git;a=commit;h=ab7eb292307152e706948a7b19164ff5e6d593d4
Acknowledgments: Name: Qualys Research Labs
Public via: http://seclists.org/oss-sec/2017/q4/385
Created glibc tracking bugs for this issue: Affects: fedora-all [bug 1524867]
Statement: This issue did not affect the versions of glibc as shipped with Red Hat Enterprise Linux 5, 6 and 7 after CVE-2017-1000366 fix: https://access.redhat.com/security/cve/cve-2017-1000366