Описание
Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.
This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for ccs should not pass them through without validation.
A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the fopen function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information.
Отчет
This vulnerability in glibc involves a heap buffer overflow when the fopen function processes an attacker-controlled mode string with an effectively empty ,ccs= extension. Exploitation is highly complex as this specific usage pattern is not common in applications within typical Red Hat Enterprise Linux environments, significantly limiting its practical applicability.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | glibc | Affected | ||
| Red Hat Enterprise Linux 6 | compat-glibc | Fix deferred | ||
| Red Hat Enterprise Linux 6 | glibc | Fix deferred | ||
| Red Hat Enterprise Linux 7 | compat-glibc | Fix deferred | ||
| Red Hat Enterprise Linux 7 | glibc | Fix deferred | ||
| Red Hat Enterprise Linux 8 | glibc | Fix deferred | ||
| Red Hat Enterprise Linux 9 | glibc | Affected | ||
| Red Hat Hardened Images | filesystem | Not affected | ||
| Red Hat Hardened Images | glibc-main-2.43-8.5.hum1 | Fixed | RHSA-2026:65339 | 08.09.2026 |
Показывать по
Дополнительная информация
Статус:
4.9 Medium
CVSS3
Связанные уязвимости
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.
Passing an effectively empty string to the `,ccs=` syntax extension of ...
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.
4.9 Medium
CVSS3