Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:4250-1

Опубликовано: 17 сент. 2026
Источник: suse-cvrf

Описание

Security update for glibc

This update for glibc fixes the following issues:

  • CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726).
  • CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723).
  • CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262).
  • CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892).
  • CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946).
  • CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921).
  • CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922).

Список пакетов

Container bci/bci-busybox:latest
glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest
glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest
glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest
glibc-2.38-150600.14.58.1
Container bci/spack:latest
glibc-devel-2.38-150600.14.58.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
glibc-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
Container suse/ltss/sle15.6/bci-base-fips:latest
glibc-2.38-150600.14.58.1
Container suse/ltss/sle15.6/sle15:latest
glibc-2.38-150600.14.58.1
Container suse/postgres:16
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
Container suse/postgres:16.15
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
Container suse/postgres:17
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
Container suse/postgres:17.11
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
Container suse/postgres:latest
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
Container suse/sle15:latest
glibc-2.38-150600.14.58.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
glibc-2.38-150600.14.58.1
glibc-32bit-2.38-150600.14.58.1
glibc-devel-2.38-150600.14.58.1
glibc-extra-2.38-150600.14.58.1
glibc-i18ndata-2.38-150600.14.58.1
glibc-info-2.38-150600.14.58.1
glibc-lang-2.38-150600.14.58.1
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
glibc-locale-base-32bit-2.38-150600.14.58.1
glibc-profile-2.38-150600.14.58.1
libnsl1-2.38-150600.14.58.1
libnsl1-32bit-2.38-150600.14.58.1
nscd-2.38-150600.14.58.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
glibc-devel-32bit-2.38-150600.14.58.1
glibc-devel-static-2.38-150600.14.58.1
glibc-utils-2.38-150600.14.58.1
SUSE Linux Enterprise Server 15 SP6-LTSS
glibc-2.38-150600.14.58.1
glibc-32bit-2.38-150600.14.58.1
glibc-devel-2.38-150600.14.58.1
glibc-devel-32bit-2.38-150600.14.58.1
glibc-devel-static-2.38-150600.14.58.1
glibc-extra-2.38-150600.14.58.1
glibc-i18ndata-2.38-150600.14.58.1
glibc-info-2.38-150600.14.58.1
glibc-lang-2.38-150600.14.58.1
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
glibc-locale-base-32bit-2.38-150600.14.58.1
glibc-profile-2.38-150600.14.58.1
glibc-utils-2.38-150600.14.58.1
libnsl1-2.38-150600.14.58.1
libnsl1-32bit-2.38-150600.14.58.1
nscd-2.38-150600.14.58.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
glibc-2.38-150600.14.58.1
glibc-32bit-2.38-150600.14.58.1
glibc-devel-2.38-150600.14.58.1
glibc-devel-32bit-2.38-150600.14.58.1
glibc-devel-static-2.38-150600.14.58.1
glibc-extra-2.38-150600.14.58.1
glibc-i18ndata-2.38-150600.14.58.1
glibc-info-2.38-150600.14.58.1
glibc-lang-2.38-150600.14.58.1
glibc-locale-2.38-150600.14.58.1
glibc-locale-base-2.38-150600.14.58.1
glibc-locale-base-32bit-2.38-150600.14.58.1
glibc-profile-2.38-150600.14.58.1
glibc-utils-2.38-150600.14.58.1
libnsl1-2.38-150600.14.58.1
libnsl1-32bit-2.38-150600.14.58.1
nscd-2.38-150600.14.58.1

Описание

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.


Затронутые продукты
Container bci/bci-busybox:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest:glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest:glibc-2.38-150600.14.58.1

Ссылки

Описание

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known.


Затронутые продукты
Container bci/bci-busybox:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest:glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest:glibc-2.38-150600.14.58.1

Ссылки

Описание

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The written value is a pointer into a tree node and is not directly attacker controlled. No affected application in common distributions has been identified.


Затронутые продукты
Container bci/bci-busybox:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest:glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest:glibc-2.38-150600.14.58.1

Ссылки

Описание

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.


Затронутые продукты
Container bci/bci-busybox:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest:glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest:glibc-2.38-150600.14.58.1

Ссылки

Описание

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.


Затронутые продукты
Container bci/bci-busybox:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest:glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest:glibc-2.38-150600.14.58.1

Ссылки

Описание

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang. Some SHIFT_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used. The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.


Затронутые продукты
Container bci/bci-busybox:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest:glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest:glibc-2.38-150600.14.58.1

Ссылки

Описание

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang. Some EUC_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used. The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117.


Затронутые продукты
Container bci/bci-busybox:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro-fips:latest:glibc-2.38-150600.14.58.1
Container bci/bci-micro:latest:glibc-2.38-150600.14.58.1
Container bci/bci-minimal:latest:glibc-2.38-150600.14.58.1

Ссылки
Уязвимость SUSE-SU-2026:4250-1