Bug 2459854 (CVE-2026-5928)
| Summary: | CVE-2026-5928 glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | ashankar, codonell, dj, fweimer, pfrankli, rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in glibc (GNU C Library). When the `ungetwc` function is called on a file stream using wide characters with specific overlapping single-byte and multi-byte encodings, it may attempt to read data outside of its allocated buffer. This can lead to the unintentional disclosure of sensitive information from memory or cause the program to crash, resulting in a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-04-20 21:02:01 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:42694 https://access.redhat.com/errata/RHSA-2026:42694 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:42733 https://access.redhat.com/errata/RHSA-2026:42733 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:42952 https://access.redhat.com/errata/RHSA-2026:42952 |