MGASA-2026-0391
Dashboard / Vulnerabilities / MGASA-2026-0391
MGASA-2026-0391
Summary: Updated glibc package fixes security vulnerabilities
Details: Potential buffer overflow in ns_sprintrrf TSIG handling path. (CVE-2026-5435) Buffer overread in ns_printrrf with corrupted RDATA field. (CVE-2026-6238) wordexp with WRDE_APPEND can return or use invalid memory. (CVE-2026-6368) Potential stack-based buffer clash during tilde expansion in wordexp. (CVE-2026-6791) Fix right-justification in strfmon. (CVE-2026-19499) SHIFT_JISX0213 decoding lacks pending character reset. (CVE-2026-77117) EUC_JISX0213 decoding lacks pending character reset. (CVE-2026-80489)
References: https://advisories.mageia.org/MGASA-2026-0391.html, https://bugs.mageia.org/show_bug.cgi?id=35262, https://www.openwall.com/lists/oss-security/2026/04/28/16, https://www.openwall.com/lists/oss-security/2026/08/11/3
Affected packages
Package
Name: glibc
Purl: pkg:rpm/mageia/glibc?arch=source&distro=mageia-10
Affected ranges
Type: ECOSYSTEM
Events:
