From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by sourceware.org (Postfix) with ESMTP id EBCC14AA51FC for ; Mon, 20 Apr 2026 20:35:57 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org EBCC14AA51FC Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org EBCC14AA51FC Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1776717358; cv=none; b=Ff157oMjauY28Fnbo863y7YGw318ERiSC1Zumv/Mm2OSI/zJulik1p/zaMMit58sZ8UZEoJp1uVReTeo2jiayGO2JsGCL3M59DA93Uou5tRKusyKqCFGA8PQoqsioHwbjLx2UvbygYvzu0nR7a6fM/QWBpHMwlMD8jWufrLOxes= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1776717358; c=relaxed/simple; bh=0TSYV4OrOCvC/SCd4HOszzMDaLdBcMOL1k8S3n7ydqU=; h=DKIM-Signature:Message-ID:Date:MIME-Version:To:From:Subject; b=VYKnrgsqTEHUdBvu4Yd9L87+kpUrHba8phcZi1z5DUK0e+CegjY6azV8Qgx+cBQOVyPfNNTIp27FXcfvgg2gb4zSFETlcEVekxHlxqL1h45avrd+lXZu8LJMcVQDTUcPZTXicjJpsk/qzwt+AsueCJ1Jyqef/w2t6UH27r9M3ZY= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org EBCC14AA51FC Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=D0HR67u3 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1776717357; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=SdD1KJYqsE/USpsqEpmAUiSxouO9/8I0CvL/o41RLAo=; b=D0HR67u3kth/uFPs0p20rYVwGy9U92n40nqhVJ1eSZVJ9JGg29/anhBwwGrewvCSzZjK7t xjgOEdTNQQv6ves8u9O18GpHG0Fqu2kikbf9WaqVu2p97kyAsdujFAya6DKQNpouu2iPB5 tUuVPqlmEK/OIZDHpNG7uGJL4Ty+F+g= Received: from mail-qk1-f197.google.com (mail-qk1-f197.google.com [209.85.222.197]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-412-S6CtV6kROeegopfAS63NJg-1; Mon, 20 Apr 2026 16:35:55 -0400 X-MC-Unique: S6CtV6kROeegopfAS63NJg-1 X-Mimecast-MFC-AGG-ID: S6CtV6kROeegopfAS63NJg_1776717355 Received: by mail-qk1-f197.google.com with SMTP id af79cd13be357-8d4c2906fdfso348676485a.2 for ; Mon, 20 Apr 2026 13:35:55 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776717354; x=1777322154; h=content-transfer-encoding:organization:subject:from:to :content-language:user-agent:mime-version:date:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=SdD1KJYqsE/USpsqEpmAUiSxouO9/8I0CvL/o41RLAo=; b=sgvl4/8vhjmkAppsKri5/rZoERWrrnXquhqonK0YfyWlbZz873+5s1gqzi3MClE/Pd AIPpL9OJilRBlCQWSt+I4wv1+qtWXRqx1jj6midRXddF0w19H+P3YXzayy+8ZEy2FNez mUfLH3w6MIRjS6pdxXhCjm2zr4tYyLGcLXN3FPlBAFwDomMxUeoh9UvIsjE4c1le18r4 UZyQ74fiefey37gn85Mnd5tB/pIgamTQFAdACrEPiibShd2rN/92FzQASO2VCt0bjTC+ I857ydsXjXEr10R2tWHAB9lGEdjrxpVHU/9iXcjzo2v2JBMDoJpnp0XszG2YtY9UZvzX 6XyA== X-Gm-Message-State: AOJu0Yxx43BiIw32aYwEZKxoryieFBzQKmUDWokFuYgz23sZipxb9ibD ND8CNSs3DgD6jKdgladm49MZsyzQKoB+Y54z+Tq+l0J8DPUl4jWaA8upXqWH/db7xPn4sKs1lmQ pMznSR4GUjehJp9K68lDKafQ1RsM7TS696CsVB6cu1dBF2P5/K2Fzw4hypGg115ofU/jEVOZwNE V1MyERNMqv8GG+80fu8vkLq5vExk8blcqG8FPNMrywpK9LiuA= X-Gm-Gg: AeBDies7dI4j3WPltXS6w+SrugLYjLlYt9YA8EQ8mSY5eWRiJL9nvYwk5tlqhhU44d3 8rEqgXnzDTBW3B2HLAN3JT3KUvJzcCs+Q1YVo83dQxb9Z2SDmRLqc4oqmeVZV+IPpgmq3787Ff8 WGoUjbhggTfrc7iacHc3+SGJE6YNav6R6/yFhHO1j8bmoZju0q7dYUSe9+urQfF5xIWGs2QypOD HQBp7yWncOm8CzprtK4TZKqlH/xwcLiHbhQnTdEHuMfbwWQKEkQcvgn4uDiBamWmXWAPQfzgGdA TIdwVlBA4S7IJVo+0LTPbSO8ESI6q3s0jUN4Whkl4CU+r0nXFqiiidRF61HCbl9EfArsB4B+Yno JneO2nMG5nzjVwG5Yam64zdN7mzfQlIx+cfwQzTJALE9pUpkiXluQcxC4j8QDv7o+K4AdSpgqyY OrOp/GTbY51E84aYrv+xgxb3HYDSGuxzWI X-Received: by 2002:a05:620a:4613:b0:8da:d152:b7de with SMTP id af79cd13be357-8e791b8d526mr2253093085a.31.1776717354205; Mon, 20 Apr 2026 13:35:54 -0700 (PDT) X-Received: by 2002:a05:620a:4613:b0:8da:d152:b7de with SMTP id af79cd13be357-8e791b8d526mr2253085985a.31.1776717353517; Mon, 20 Apr 2026 13:35:53 -0700 (PDT) Received: from [192.168.0.116] ([198.48.244.52]) by smtp.gmail.com with ESMTPSA id af79cd13be357-8e7d5fe90a4sm916636285a.9.2026.04.20.13.35.52 for (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 20 Apr 2026 13:35:52 -0700 (PDT) Message-ID: Date: Mon, 20 Apr 2026 16:35:51 -0400 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird To: libc-announce@sourceware.org From: Carlos O'Donell Subject: The GNU C Library security advisories update for 2026-04-20 Organization: Red Hat, LLC. X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: UuoU1NQhiR_Q8nNOKdZDQkIy7Hg4yULADxeFtAXIMr4_1776717355 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Status: No, score=-5.7 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,RCVD_IN_DNSWL_NONE,SPF_HELO_PASS,SPF_NONE,TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org List-Id: The following security advisories have been published: GLIBC-SA-2026-0008: =================== Static buffer overflow in deprecated nis_local_principal The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof a crafted response to a UDP request generated by this function and overwrite neighboring static data in the requesting application. NIS support is obsolete and has been deprecated in the GNU C Library since version 2.26 and is only maintained for legacy usage. Applications should port away from NIS to more modern identity and access management services. CVE-Id: CVE-2026-5358 Public-Date: 2026-04-10 Reported-by: Rahul Hoysala GLIBC-SA-2026-0009: =================== scanf %mc off-by-one heap buffer overflow Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow. The bug is in the buffer growth formula in __vfscanf_internal, which under-allocates by one byte during realloc expansion, allowing a controlled single-byte overwrite past the end of the heap buffer. The impact is limited by the fact that to execute the overwrite you need both user controlled input data and a specific choice of maximum width that yields a smaller than needed allocation. The latter point has to take into account malloc's particular chunk size rounding process. The "%[width]mc" format specififer does not appear to have notable use in major Linux-based OS distributions, due to which the real world impact may be limited to bespoke use cases. CVE-Id: CVE-2026-5450 Public-Date: 2026-03-19 Vulnerable-Commit: 874aa52349cc111d1f6ea5dff24bb14c306714e0 (2.7) Reported-by: Rocket Ma GLIBC-SA-2026-0010: =================== Potential buffer under-read in ungetwc Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets. CVE-Id: CVE-2026-5928 Public-Date: 2026-03-17 Reported-by: Rocket Ma Vulnerable-Commit: d64b6ad07585b8a37e5fecc9a47fcee766d52ede (2.1.1-89) Notes: ====== Published advisories are available directly in the project git repository: https://sourceware.org/git/?p=glibc.git;a=tree;f=advisories;hb=HEAD