Bug 2459854 (CVE-2026-5928) - CVE-2026-5928 glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
Summary: CVE-2026-5928 glibc: glibc: Information disclosure or denial of service via u...
Keywords:
Status: NEW
Alias: CVE-2026-5928
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-20 21:02 UTC by OSIDB Bzimport
Modified: 2026-07-31 08:01 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:47045 0 None None None 2026-07-28 11:24:11 UTC
Red Hat Product Errata RHBA-2026:48661 0 None None None 2026-07-30 08:37:38 UTC
Red Hat Product Errata RHBA-2026:48662 0 None None None 2026-07-30 11:24:00 UTC
Red Hat Product Errata RHSA-2026:42694 0 None None None 2026-07-21 11:58:18 UTC
Red Hat Product Errata RHSA-2026:42733 0 None None None 2026-07-21 14:23:34 UTC
Red Hat Product Errata RHSA-2026:42952 0 None None None 2026-07-22 02:46:24 UTC

Description OSIDB Bzimport 2026-04-20 21:02:01 UTC
Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.

A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Comment 3 errata-xmlrpc 2026-07-21 11:58:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:42694 https://access.redhat.com/errata/RHSA-2026:42694

Comment 4 errata-xmlrpc 2026-07-21 14:23:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:42733 https://access.redhat.com/errata/RHSA-2026:42733

Comment 5 errata-xmlrpc 2026-07-22 02:46:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:42952 https://access.redhat.com/errata/RHSA-2026:42952


Note You need to log in before you can comment on or make changes to this bug.