Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95495.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-95495
Upstream
Published
2026-08-10T19:17:30Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-6368 affecting package glibc 2.38-20
Details

Calling wordexp with WRDEAPPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the wewordv member, which on subsequent calls to wordfree may abort the process.

References

Affected packages

Azure Linux:3 / glibc

Package

Name
glibc
Purl
pkg:rpm/azure-linux/glibc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.38-20

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95495.json"