CVE-2026-19499: Buffer overflow in strfmon and strfmon_l right-justification padding
Buffer overflow in strfmon and strfmonl right-justification padding
Other sources
Calling strfmon and strfmonl in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.
Exploitation requires an application code path that calls strfmon or strfmonl with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.
At the time of publication, no network-facing application impact is known.
— NVD
Summary: Buffer Overflow in strfmon right-justification padding: <br/> out-of-bounds write in the caller-supplied output buffer caused by using <br/> the post-padding length for the in-place memmove.<br/> Requirements to exploit: A reachable application code path must invoke <br/> strfmon or strfmonl with right-justified width padding and a <br/> destination buffer that is large enough for printfbufferpad to <br/> succeed but not large enough for the subsequent overlong memmove. This <br/> may arise through attacker-influenced formatting input or through a fixed <br/> susceptible formatting pattern in the calling application.<br/>
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/glibcto a version that resolves this vulnerability.Fixed in 2.43-5
Event History
Frequently Asked Questions
What application conditions make this issue exploitable?
A reachable code path must call strfmon or strfmon_l using right-justified width padding. Its caller-supplied destination buffer must be large enough for __printf_buffer_pad to succeed but too small for the later overlong memmove.
Does exploitation require attacker-controlled input?
Not necessarily. Attacker-influenced formatting input may create the required conditions, but a fixed formatting pattern in the application can also be susceptible.
Which systems are realistically exposed?
Systems using Debian glibc are exposed only where an application reaches a susceptible strfmon or strfmon_l formatting path with the required padding and buffer-size conditions.