https://seclists.org/oss-sec/2026/q3/781: The GNU C Library security advisories update for 2026-09-14

Published Sep 14, 2026
·
Updated

Affected Software

3 affected components
GNU GNU C Library (glibc)>=2.38<=2.44
GNU GNU C Library (glibc)>=2.1<=2.44
GNU GNU C Library (glibc)>=2.3<=2.44

Frequently Asked Questions

1

Which applications are affected in practice?

Applications using GNU C Library versions 2.38 through 2.44 are affected only if they call strfmon or strfmon_l with right-justified width padding and use a destination buffer that can hold the padding but is too small for the internal memmove operation. The susceptible field width or format may be attacker-controlled or may be a fixed pattern in the application.

2

Is there known network-facing exposure?

At the time of publication, no network-facing application impact was known. Exploitation still depends on reaching a susceptible application code path and supplying or triggering the relevant formatting conditions.

3

How can we determine whether our code is exposed?

Review uses of strfmon and strfmon_l for format conversions with right-justified width padding. Verify that caller-supplied output buffers are sufficiently sized not only for the padding to succeed, but also for the internal memmove operation; GNU C Library 2.45 contains the listed fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203