CVE-2026-19499: Buffer overflow in strfmon and strfmon_l right-justification padding

Published Aug 25, 2026
·
Updated

Buffer overflow in strfmon and strfmonl right-justification padding

Other sources

Calling strfmon and strfmonl in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.

Exploitation requires an application code path that calls strfmon or strfmonl with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.

At the time of publication, no network-facing application impact is known.

— NVD

Summary: Buffer Overflow in strfmon right-justification padding: <br/> out-of-bounds write in the caller-supplied output buffer caused by using <br/> the post-padding length for the in-place memmove.<br/> Requirements to exploit: A reachable application code path must invoke <br/> strfmon or strfmonl with right-justified width padding and a <br/> destination buffer that is large enough for printfbufferpad to <br/> succeed but not large enough for the subsequent overlong memmove. This <br/> may arise through attacker-influenced formatting input or through a fixed <br/> susceptible formatting pattern in the calling application.<br/>

— Red Hat

Affected Software

1 affected componentFixes available
debian/glibc<=2.36-9+deb12u14, <=2.36-9+deb12u7, <=2.41-12+deb13u4
2.43-5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/glibc to a version that resolves this vulnerability.

    Fixed in 2.43-5

Event History

Aug 25, 2026
Data Sourced
via Red Hat·07:36 AM
DescriptionSeverityAffected Software
Sep 10, 2026
Data Sourced
via Ubuntu·05:33 PM
RemedyDescriptionSeverityAffected Software
Sep 13, 2026
Data Sourced
via Debian·05:36 PM
DescriptionAffected Software
Sep 14, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Sep 16, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What application conditions make this issue exploitable?

A reachable code path must call strfmon or strfmon_l using right-justified width padding. Its caller-supplied destination buffer must be large enough for __printf_buffer_pad to succeed but too small for the later overlong memmove.

2

Does exploitation require attacker-controlled input?

Not necessarily. Attacker-influenced formatting input may create the required conditions, but a fixed formatting pattern in the application can also be susceptible.

3

Which systems are realistically exposed?

Systems using Debian glibc are exposed only where an application reaches a susceptible strfmon or strfmon_l formatting path with the required padding and buffer-size conditions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203