Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98042.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-98042
Upstream
  • CVE-2026-18374
Published
2026-08-27T20:17:03Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-18374 affecting package glibc 2.38-20
Details

Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.

This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for ccs should not pass them through without validation.

References

Affected packages

Azure Linux:3 / glibc

Package

Name
glibc
Purl
pkg:rpm/azure-linux/glibc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.38-20

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98042.json"