CVE-2026-19542: Stack-based out-of-bounds write in tdelete during tree rebalancing

Published Sep 14, 2026
·
Updated

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.

The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The written value is a pointer into a tree node and is not directly attacker controlled. No affected application in common distributions has been identified.

Other sources

Out-of-bounds stack array access in tdelete

Debian

Affected Software

1 affected componentFixes available
debian/glibc<=2.36-9+deb12u14, <=2.36-9+deb12u7, <=2.41-12+deb13u4
2.43-5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/glibc to a version that resolves this vulnerability.

    Fixed in 2.43-5

Event History

Sep 10, 2026
Data Sourced
via Ubuntu·05:33 PM
RemedyDescriptionSeverityAffected Software
Sep 13, 2026
Data Sourced
via Debian·05:36 PM
DescriptionAffected Software
Sep 14, 2026
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which software package is identified as affected?

The record identifies debian/glibc.

2

Does the available information specify affected versions, fixed versions, or a workaround?

No. The supplied data does not include affected or fixed version ranges, configuration conditions, or mitigation guidance.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203