logo

Decades-Old Flaw & New Heap Corruption: Critical glibc Bugs Revealed

ID: 59651ddd-a14f-5c50-9d00-ea5a7c460bde

STIX ID: report--59651ddd-a14f-5c50-9d00-ea5a7c460bde

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

The GNU C Library maintainers disclosed two security flaws: CVE-2026-0861 is a high-severity integer overflow in memory alignment functions (memalign/posix_memalign/aligned_alloc) that can cause heap corruption if an attacker controls both size and alignment with an extremely large size; CVE-2026-0915 is a decades-old information leak in getnetbyaddr/getnetbyaddr_r that can pass unmodified stack contents to a DNS resolver when querying a zero-valued network, potentially aiding ASLR bypass. Both affect broad ranges of glibc versions, but the advisory notes high exploitation complexity and uncommon usage patterns; administrators are advised to assess distribution impact and apply patches where available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.