VDB
CVE-2026-18374
CVE-2026-18374
PUBLISHED
CVSS 4.9 MEDIUM
Reported by glibc · Published August 27, 2026
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.
Risk Scores
CVSS 3.1
4.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| The GNU C Library | glibc | 0 |
| The GNU C Library | glibc | 0, 0 |
| wolfi | glibc-2.44 | 0, 0, 0 |
| chainguard | glibc-2.44 | 0, 0 |
Timeline
- Aug 27, 2026 Coalition ESS Score
- Aug 27, 2026 CVE Published
- Aug 28, 2026 EPSS Score
- Sep 2, 2026 Security Advisory
- Sep 3, 2026 CVE Updated
References
- issue-tracking
- vendor-advisory
- http://www.openwall.com/lists/oss-security/2026/08/27/6 url