Описание
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.
A flaw was found in glibc (GNU C Library). This vulnerability occurs when an application uses the scanf family of functions with a %mc format specifier, which is used for dynamically allocating memory for character input, and provides an explicit width greater than 1024. This specific combination can lead to a one-byte heap buffer overflow, potentially allowing an attacker to corrupt memory.
Отчет
Because this flaw requires that an affected application call the affected functions with an attacker-supplied value, Red Hat assesses the Attack Complexity of this flaw as High. Additionally, the flaw overflows a single byte onto the heap, so meaningful exploitation requires that the heap is structured such that a single byte can lead to an attacker-controlled outcome, or that the affected functions can be invoked with an attacker-controlled buffer base address. Regarding Attack Vector and Privileges Required, Red Hat assesses these elements as Local and Low respectively, as remote unauthenticated exploitation would require all the conditions above in a library client that listened on a network port and processed attacker-controllable data with the affected library functions.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | compat-glibc | Will not fix | ||
| Red Hat Enterprise Linux 10 | glibc | Fixed | RHSA-2026:33092 | 30.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | glibc | Fixed | RHSA-2026:33170 | 29.06.2026 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | glibc | Fixed | RHSA-2026:37395 | 09.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | glibc | Fixed | RHSA-2026:34211 | 01.07.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | compat-glibc | Fixed | RHSA-2026:37396 | 09.07.2026 |
| Red Hat Enterprise Linux 8 | glibc | Fixed | RHSA-2026:33126 | 29.06.2026 |
| Red Hat Enterprise Linux 8 | glibc | Fixed | RHSA-2026:33126 | 29.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | glibc | Fixed | RHSA-2026:36643 | 08.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | glibc | Fixed | RHSA-2026:36643 | 08.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.
Calling the scanf family of functions with a %mc (malloc'd character m ...
EPSS
5 Medium
CVSS3