CVE-2026-3904Disclosure(gnu / glibc)

LOWCVSS 6.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses the memcmp function with inputs that may be concurrently modified by another thread, potentially resulting in spurious cache misses, which in itself is not a security issue.  However in the GNU C Library version 2.36 an optimized implementation of memcmp was introduced for x86_64 which could crash when invoked with such undefined behaviour, turning this into a potential crash of the nscd client and the application that uses it. This implementation was backported to the 2.35 branch, making the nscd client in that branch vulnerable as well.  Subsequently, the fix for this issue was backported to all vulnerable branches in the GNU C Library repository. It is advised that distributions that may have cherry-picked the memcpy SSE2 optimization in their copy of the GNU C Library, also apply the fix to avoid the potential crash in the nscd client.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-366

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-15: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-15: 103-1203-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-3904,GLIBC-SA-2026-0004: glibc: nscd client crash on x86_64 under high nscd load https://www.openwall.com/lists/oss-security/2026/03/11/5 NSS-backed functions that support caching via nscd [...] may call memcmp on inputs that are concurrently modified by other processes or threads and crash

    Post summary

    The post announces a glibc vulnerability (CVE-2026-3904) where nscd client crashes under high load due to a concurrent memcmp race; no PoC, exploit, or patch details are provided.

    00052489
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3904 Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems,… https://www.cve.org/CVERecord?id=CVE-2026-3904

    Post summary

    The text briefly announces a potential glibc 2.36 issue involving nscd under high load on x86_64 systems, providing limited technical details but no evidence of exploitation or mitigation.

    00000135
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more