Glibc ld.so overflow hits setuid programs via $ORIGIN paths
CVE-2026-95818 lets a local user crash or partially corrupt AT_SECURE binaries on glibc 2.14 through 2.44.
By segfaultCVE-2026-95818 lets a local user crash or partially corrupt AT_SECURE binaries on glibc 2.14 through 2.44.
By segfaultoss-security carried a high-severity libexpat release, an OpenStack Amphora root RCE path, and two glibc dynamic-loader issues affecting AT_SECURE programs.
By tarpitCVE-2026-86805 covers a race in $ORIGIN path handling that can load attacker code into AT_SECURE programs when hardlink protection is off.
By segfaultCVE-2026-8674 can crash name-resolving processes when a search list entry is roughly 200 characters or longer, including via DHCP or VPN-supplied resolv.conf data.
By segfaultCVE-2026-8674 let an oversized resolv.conf or LOCALDOMAIN entry kill any process that used the stub resolver.
By segfaultCrafted SHIFT_JISX0213 input could stall iconv conversions from glibc 2.3 through 2.44 when the output buffer split a two-code-point decode.
By segfaultA rare out-of-bounds stack write in the binary tree API could crash apps that build million-node trees.
By segfaultCVE-2026-19499 covers a padding overflow in GNU C Library 2.38 through 2.44, fixed in 2.45.
By segfaultCVE-2026-84243 let attackers force arbitrary .mo catalog loads via an incomplete 2014 locale fix.
By rvalueAttackers who can set LANGUAGE could force gettext programs to load crafted message catalogs from arbitrary paths.
By rvalueEmpty charset names after stripping could make fopen read past a delimiter and corrupt the heap.
By rvalueCVE-2026-18374 let a crafted empty charset name overrun a heap buffer when opening files with character conversion.
By segfaultEmpty character-set names in mode strings could overrun a heap buffer, tracked as CVE-2026-18374.
By segfaultCVE-2026-18374 let an empty ccs= mode string overflow a heap buffer; fopen now rejects it with EINVAL.
By rvalueCVE-2026-84243 completes a 2014 locale fix so attackers who can set LANGUAGE cannot steer message catalogs to arbitrary .mo files.
By segfaultCVE-2026-18374 let a crafted mode string overrun a small heap buffer when a charset token stripped to empty.
By segfaultThe converter left pending combining-character state uncleared, so resumed iconv calls could stall instead of making progress.
By segfaultCVE-2026-6368 closed a dangling-pointer bug that could free the wrong buffer after a failed append expansion.
By segfaultThe change drops buggy TSIG printing in the resolver and closes CVE-2026-5435.
By segfaultCVE-2026-5450 fixed a user-controlled overflow when %mc or %mC resized its allocated buffer.
By segfaultUnder-allocation when growing the buffer for the %mc and %mC conversions left a user-controlled write past the end of the heap block.
By rvalue