logo

Three Silent Vulnerabilities Discovered in the glibc Core

ID: 25cf0881-a0ec-5bfa-894c-07763555138f

STIX ID: report--25cf0881-a0ec-5bfa-894c-07763555138f

Feed Name: securityonline.info

Threat Score
40/100

Date Published: 2026-04-21

Date Updated: 2026-04-23

Author: Ddos

...
...

The GNU C Library (glibc) has three disclosed vulnerabilities affecting versions up to 2.43: `CVE-2026-5358` (static buffer overflow in `nis_local_principal` via crafted UDP responses), `CVE-2026-5450` (heap buffer overflow in `scanf` with the `%mc` specifier due to a one-byte under-allocation), and `CVE-2026-5928` (an `ungetwc` implementation bug that can cause heap under-read and potential disclosure). While these issues are technically serious, the report notes limited real-world exploitability (deprecated NIS usage, rare `%mc` usage, and Unicode mitigations) and advises updating glibc to versions newer than `2.43`.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.