Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5450

Опубликовано: 20 апр. 2026
Источник: debian
EPSS Низкий

Описание

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.42-17package
glibcno-dsatrixiepackage
glibcno-dsabookwormpackage
glibcpostponedbullseyepackage

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=34008

  • https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0009

  • Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=839898777226a3ed88c0859f25ffe712519b4ead

  • "%mc is not really usable unless bug 12701 is fixed as well" cf.

  • https://sourceware.org/bugzilla/show_bug.cgi?id=34008#c2

EPSS

Процентиль: 36%
0.00451
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

CVSS3: 5
redhat
3 месяца назад

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

CVSS3: 9.8
nvd
3 месяца назад

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

msrc
3 месяца назад

scanf %mc off-by-one heap buffer overflow

CVSS3: 9.8
github
3 месяца назад

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

EPSS

Процентиль: 36%
0.00451
Низкий