CVE-2026-6791: Potential stack-based buffer clash during tilde expansion in wordexp

Published Aug 10, 2026
·
Updated

When expanding paths that begin with a tilde (~) followed by a username, the internal parsetilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.

Affected Software

1 affected component
wordexp

Event History

Aug 10, 2026
CVE Published
via MITRE·06:41 PM
Data Sourced
via MITRE·06:41 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-6791?

CVE-2026-6791 has a risk level of 33, indicating a potential impact on system security.

2

How do I fix CVE-2026-6791?

To mitigate CVE-2026-6791, update the affected software to the latest version that has addressed the stack-based buffer clash.

3

What systems are affected by CVE-2026-6791?

CVE-2026-6791 affects systems that utilize the wordexp function for path expansion that includes username tilde notation.

4

What does CVE-2026-6791 vulnerability entail?

CVE-2026-6791 involves a potential stack-based buffer clash when expanding paths with a tilde and username, risking arbitrary code execution.

5

Is CVE-2026-6791 remotely exploitable?

CVE-2026-6791 can be exploited locally as it relies on user-submitted paths that could lead to a buffer overflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203