CVE-2026-0915Patch(gnu / glibc)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu glibc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-908

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-01-31: 101-2801-3001-31
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 URGENT SYSTEM ADMIN ALERT: Critical glibc security update for Rocky Linux 10 patches two dangerous vulnerabilities (CVE-2026-0861 & CVE-2026-0915). Read more:👉 https://tinyurl.com/2p8ycrey #Rocky_Linux #Security https://t.co/J67U5K8M3m

    Post summary

    The tweet announces that Rocky Linux 10 should apply a critical glibc security update to patch CVE-2026-0861 and CVE-2026-0915.

    0000082
    1.3K followersView on X
  • Angsuman Chakraborty ✪@angsuman
    Patch

    CVE-2026-0915: GNU C Library Fixes a Security Issue Present Since 1996 https://www.phoronix.com/news/Glibc-Security-Fix-For-1996-Bug

    Post summary

    The headline indicates that a long‑standing vulnerability in the GNU C Library was fixed, but offers no concrete details on the patch, technical aspects, or exploitation.

    0000026
    7.5K followersView on X
  • Ozgur Yuksel@XceptN
    Patch

    CVE-2026-0915: GNU C Library Fixes A Security Issue Present Since 1996

    Post summary

    The advisory notes that CVE-2026-0915 has been fixed in the GNU C Library, but provides no further technical or exploit details.

    0000046
    12.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more