CVE-2026-5450

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

History

23 Apr 2026, 15:33

Type Values Removed Values Added
CWE CWE-787
References () https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u - () https://inbox.sourceware.org/libc-announce/b11f0003-6ec1-4bd6-b9de-9e38a4efeca3@redhat.com/T/#u - Third Party Advisory
References () https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 - () https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 - Exploit, Issue Tracking
First Time Gnu
Gnu glibc
CPE cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

21 Apr 2026, 20:17

Type Values Removed Values Added
References () https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 - () https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

20 Apr 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-20 21:16

Updated : 2026-04-23 15:33


NVD link : CVE-2026-5450

Mitre link : CVE-2026-5450

CVE.ORG link : CVE-2026-5450


JSON object : View

Products Affected

gnu

  • glibc
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write