Source: glibc
Version: 2.43-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glibc.

CVE-2026-18374[0]:
| Passing an effectively empty string to the `,ccs=` syntax extension
| of the mode argument in the `fopen` function in the GNU C Library
| version 2.45 or earlier may result in a heap buffer overflow when
| the mode string input to the function is attacker controlled.
| This usage pattern is not seen in applications in common GNU/Linux
| distributions and applications that process user-supplied values for
| `ccs` should not pass them through without validation.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18374
    https://www.cve.org/CVERecord?id=CVE-2026-18374
[1] 
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015

Please adjust the affected versions in the BTS as needed.

Rgards,
Salvatore

Reply via email to