Source: glibc Version: 2.43-5 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for glibc. CVE-2026-95818[0]: | A stack-based buffer overflow in the dynamic loader (ld.so) of the | GNU C Library (glibc) versions 2.14 through 2.44 allows a local | attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) | programs. When such a program's DT_RPATH or DT_RUNPATH begins with | $ORIGIN and is followed by NUL or '/' the loader both reads past the | end of the path buffer and writes past the end of a stack-allocated | internal buffer. The corrupted loader stack can lead to a loader | crash (denial of service) and limited disclosure of process memory. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-95818 https://www.cve.org/CVERecord?id=CVE-2026-95818 [1] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0023 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

