Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5450

Опубликовано: 20 апр. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the scanf family of functions with a %mc format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.

Отчет

Because this flaw requires that an affected application call the affected functions with an attacker-supplied value, Red Hat assesses the Attack Complexity of this flaw as High. Additionally, the flaw overflows a single byte onto the heap, so meaningful exploitation requires that the heap is structured such that a single byte can lead to an attacker-controlled outcome, or that the affected functions can be invoked with an attacker-controlled buffer base address. Regarding Attack Vector and Privileges Required, Red Hat assesses these elements as Local and Low respectively, as remote unauthenticated exploitation would require all the conditions above in a library client that listened on a network port and processed attacker-controllable data with the affected library functions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-glibcWill not fix
Red Hat Enterprise Linux 10glibcFixedRHSA-2026:3309230.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportglibcFixedRHSA-2026:3317029.06.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONglibcFixedRHSA-2026:3739509.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportglibcFixedRHSA-2026:3421101.07.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportcompat-glibcFixedRHSA-2026:3739609.07.2026
Red Hat Enterprise Linux 8glibcFixedRHSA-2026:3312629.06.2026
Red Hat Enterprise Linux 8glibcFixedRHSA-2026:3312629.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportglibcFixedRHSA-2026:3664308.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnglibcFixedRHSA-2026:3664308.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2459853glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

EPSS

Процентиль: 40%
0.00502
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

CVSS3: 9.8
nvd
3 месяца назад

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

msrc
3 месяца назад

scanf %mc off-by-one heap buffer overflow

CVSS3: 9.8
debian
3 месяца назад

Calling the scanf family of functions with a %mc (malloc'd character m ...

rocky
30 дней назад

Moderate: glibc security, bug fix, and enhancement update

EPSS

Процентиль: 40%
0.00502
Низкий

5 Medium

CVSS3