AT_SECURE program buffer overflow via $ORIGIN processing
A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C
Library (glibc) versions 2.14 through 2.44 allows a local attacker to
crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.
When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is
followed by NUL or '/' the loader both reads past the end of the path
buffer and writes past the end of a stack-allocated internal buffer.
The corrupted loader stack can lead to a loader crash (denial of
service) and limited disclosure of process memory.
CVE-Id: CVE-2026-95818
Public-Date: 2026-08-14
Vulnerable-Commit: 47c3cd7a74e8c089d60d603afce6d9cf661178d6 (2.13-113)
Fix-Commit: ed0c137b97eb940b4b64981e84ed806d3276edd9 (2.45)
Reported-by: AISLE in partnership with Red Hat
CVSS: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - 3.6