GLIBC-SA-2026-0023 on Cyberus Linux 26.05
Aliases: GLIBC-SA-2026-0023, CVE-2026-95818
Packages: glibc
Status: In Progress
Advisory Information
AT_SECURE program buffer overflow via $ORIGIN processing A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory. CVE-Id: CVE-2026-95818 Public-Date: 2026-08-14 Vulnerable-Commit: 47c3cd7a74e8c089d60d603afce6d9cf661178d6 (2.13-113) Fix-Commit: ed0c137b97eb940b4b64981e84ed806d3276edd9 (2.45) Reported-by: AISLE in partnership with Red Hat CVSS: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - 3.6
Updates
2026-10-09 16:28 CEST
Metadata changes:
- Status for package
glibc: “In Progress” (31fee2d1fdfd35ff81631b022887d6999296aaf9)
2026-09-24 17:47 CEST
Metadata changes:
- Status for package
glibc: “Plausible”
2026-09-24 17:29 CEST
Metadata changes:
- Status for package
glibc: “New”