CVE-2026-5450

medium
Published 2026-06-29 Β· Modified 2026-06-29
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHSA-2026:33226: glibc security, bug fix, and enhancement update (Moderate)

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width Red Hat statement Because this flaw requires that an affected application call the affected functions with an attacker-supplied value, Red Hat assesses the Attack Complexity of this flaw as High. Additionally, the flaw overflows a single byte onto the heap, so meaningful exploitation requires…

Description

glibc: glibc: Heap Buffer Overflow in `scanf` with `%mc` format specifier and large width

Red Hat statement

Because this flaw requires that an affected application call the affected functions with an attacker-supplied value, Red Hat assesses the Attack Complexity of this flaw as High. Additionally, the flaw overflows a single byte onto the heap, so meaningful exploitation requires that the heap is structured such that a single byte can lead to an attacker-controlled outcome, or that the affected functions can be invoked with an attacker-controlled buffer base address. Regarding Attack Vector and Privileges Required, Red Hat assesses these elements as Local and Low respectively, as remote unauthenticated exploitation would require all the conditions above in a library client that listened on a network port and processed attacker-controllable data with the affected library functions.

CVSS v3: 5.0 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10.0 Extended Update Supportglibc-0:2.39-46.el10_0.5RHSA-2026:331702026-06-29T00:00:00Z
Red Hat Enterprise Linux 8glibc-0:2.28-251.el8_10.38RHSA-2026:331262026-06-29T00:00:00Z
Red Hat Enterprise Linux 8glibc-0:2.28-251.el8_10.38RHSA-2026:331262026-06-29T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportglibc-0:2.28-189.13.el8_6RHSA-2026:332272026-06-29T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-Onglibc-0:2.28-189.13.el8_6RHSA-2026:332272026-06-29T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Serviceglibc-0:2.28-225.el8_8.17RHSA-2026:332282026-06-29T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionsglibc-0:2.28-225.el8_8.17RHSA-2026:332282026-06-29T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionsglibc-0:2.34-60.el9_2.20RHSA-2026:332312026-06-29T00:00:00Z
Red Hat Hardened Imagesglibc-main-2.42-12.hum1RHSA-2026:127402026-05-01T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10glibcAffected
Red Hat Enterprise Linux 6compat-glibcWill not fix
Red Hat Enterprise Linux 6glibcAffected
Red Hat Enterprise Linux 7compat-glibcAffected
Red Hat Enterprise Linux 7glibcAffected
Red Hat Enterprise Linux 9glibcAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Apply commands

bash fix
Apply RHSA-2026:33170 for Red Hat Enterprise Linux 10.0 Extended Update Support
yum update -y glibc
# or:
dnf upgrade -y glibc

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 6Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat OpenShift Container Platform 4Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Fixed 2.42-17
forky Fixed 2.42-17
bullseye Affected β€”
bookworm Affected β€”
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.