CVE-2026-5928Patch(gnu / glibc)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu glibc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-127

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-28: 104-2004-2104-28
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-212
General1Patch1
2026-04-281
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    glibc version 2.43 and older face heap overflows and memory leaks. Learn about CVE-2026-5358, CVE-2026-5450, and CVE-2026-5928. Update your Linux systems now. #glibc #LinuxSecurity #CyberSecurity #InfoSec #OpenSource #CVE #Vulnerability #SysAdmin https://securityonline.info/glibc-vulnerabilities-2026-linux-security-flaws/ https://t.co/RnpzeVqzJk

    Post summary

    The post warns that glibc versions ≤2.43 suffer from heap overflows and memory leaks (CVE‑2026‑5358, 5450, 5928) and urges users to update their systems.

    22081787
    12.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    3 new glibc SAs https://www.openwall.com/lists/oss-security/2026/04/20/9 GLIBC-SA-2026-0008,CVE-2026-5358: Static buffer overflow in deprecated nis_local_principal GLIBC-SA-2026-0009,CVE-2026-5450: scanf %mc off-by-one heap buffer overflow GLIBC-SA-2026-0010,CVE-2026-5928: Potential buffer under-read in ungetwc

    Post summary

    Three new glibc security advisories were published, each detailing a different buffer overflow or under‑read flaw associated with CVE‑2026‑5358, CVE‑2026‑5450, and CVE‑2026‑5928.

    00040399
    4.7K followersView on X
  • Vito Botta@vitobotta
    Patch

    Just read about three recent CVEs in glibc, the library that underpins basically every Linux system on the planet. The scariest one is CVE-2026-5450, a heap buffer overflow in scanf with the %mc format specifier, CVSS 9.8. Versions 2.7 through 2.43 are affected. That's decades of glibc releases. Then there's CVE-2026-5358, a buffer overflow in the obsolete nis_local_principal function, and CVE-2026-5928, a buffer under-read in ungetwc that can leak heap data. Patch your systems. When glibc has bugs, we can assume that everything built on top of it has potential bugs.

    Post summary

    Three recent glibc CVEs are described with technical specifics, and the text stresses patching affected systems.

    0000092
    956 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5928 Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodin… https://www.cve.org/CVERecord?id=CVE-2026-5928

    Post summary

    The post merely references CVE-2026-5928 with a brief technical snippet and a link to its record, lacking any PoC, exploit code, or mitigation details.

    0000096
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more