Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2026-95818

2 дня назад

A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2026-95818

2 дня назад

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.

CVSS3: 3.6
EPSS: Низкий
msrc логотип

CVE-2026-95818

около 15 часов назад

AT_SECURE program buffer overflow via $ORIGIN processing

CVSS3: 3.6
EPSS: Низкий
debian логотип

CVE-2026-95818

2 дня назад

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU ...

CVSS3: 3.6
EPSS: Низкий
github логотип

GHSA-h8x4-734c-9753

2 дня назад

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.

CVSS3: 3.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-95818

A flaw was found in glibc, the GNU C Library. A local attacker can exploit a stack-based buffer overflow in the dynamic loader (ld.so) when a setuid/setgid (AT_SECURE) program's DT_RPATH or DT_RUNPATH begins with $ORIGIN followed by a null character or a slash. This vulnerability allows the attacker to crash the loader, leading to a denial of service, and potentially disclose limited process memory.

CVSS3: 5.8
0%
Низкий
2 дня назад
nvd логотип
CVE-2026-95818

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.

CVSS3: 3.6
0%
Низкий
2 дня назад
msrc логотип
CVE-2026-95818

AT_SECURE program buffer overflow via $ORIGIN processing

CVSS3: 3.6
0%
Низкий
около 15 часов назад
debian логотип
CVE-2026-95818

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU ...

CVSS3: 3.6
0%
Низкий
2 дня назад
github логотип
GHSA-h8x4-734c-9753

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.

CVSS3: 3.6
0%
Низкий
2 дня назад

Уязвимостей на страницу