Source: glibc Version: 2.43-4 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for glibc. CVE-2026-18374[0]: | Passing an effectively empty string to the `,ccs=` syntax extension | of the mode argument in the `fopen` function in the GNU C Library | version 2.45 or earlier may result in a heap buffer overflow when | the mode string input to the function is attacker controlled. | This usage pattern is not seen in applications in common GNU/Linux | distributions and applications that process user-supplied values for | `ccs` should not pass them through without validation. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-18374 https://www.cve.org/CVERecord?id=CVE-2026-18374 [1] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015 Please adjust the affected versions in the BTS as needed. Rgards, Salvatore

