Decades-Old Flaw & New Heap Corruption: Critical glibc Bugs Revealed
ID: 59651ddd-a14f-5c50-9d00-ea5a7c460bde
STIX ID: report--59651ddd-a14f-5c50-9d00-ea5a7c460bde
Feed Name: securityonline.info
The GNU C Library maintainers disclosed two security flaws: CVE-2026-0861 is a high-severity integer overflow in memory alignment functions (memalign/posix_memalign/aligned_alloc) that can cause heap corruption if an attacker controls both size and alignment with an extremely large size; CVE-2026-0915 is a decades-old information leak in getnetbyaddr/getnetbyaddr_r that can pass unmodified stack contents to a DNS resolver when querying a zero-valued network, potentially aiding ASLR bypass. Both affect broad ranges of glibc versions, but the advisory notes high exploitation complexity and uncommon usage patterns; administrators are advised to assess distribution impact and apply patches where available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
