Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18374

Опубликовано: 27 авг. 2026
Источник: redhat
CVSS3: 4.9

Описание

Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for ccs should not pass them through without validation.

A flaw was found in the GNU C Library (glibc). This vulnerability could allow an attacker with local access to trigger a heap buffer overflow by manipulating how the fopen function handles certain input. This could lead to minor disruptions in system operations or limited access to sensitive information.

Отчет

This vulnerability in glibc involves a heap buffer overflow when the fopen function processes an attacker-controlled mode string with an effectively empty ,ccs= extension. Exploitation is highly complex as this specific usage pattern is not common in applications within typical Red Hat Enterprise Linux environments, significantly limiting its practical applicability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10glibcAffected
Red Hat Enterprise Linux 6compat-glibcFix deferred
Red Hat Enterprise Linux 6glibcFix deferred
Red Hat Enterprise Linux 7compat-glibcFix deferred
Red Hat Enterprise Linux 7glibcFix deferred
Red Hat Enterprise Linux 8glibcFix deferred
Red Hat Enterprise Linux 9glibcAffected
Red Hat Hardened ImagesfilesystemNot affected
Red Hat Hardened Imagesglibc-main-2.43-8.5.hum1FixedRHSA-2026:6533908.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=2525256glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
25 дней назад

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.

CVSS3: 4.9
nvd
25 дней назад

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.

CVSS3: 4.9
debian
25 дней назад

Passing an effectively empty string to the `,ccs=` syntax extension of ...

CVSS3: 4.9
github
24 дня назад

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.

suse-cvrf
5 дней назад

Security update for glibc

4.9 Medium

CVSS3