The one-byte over-read is in the POWER8-optimised strncasecmp
(GLIBC-SA-2026-0024).
Echo builds glibc exclusively for amd64 and arm64, whose strncasecmp
implementations are separate and unaffected, so the vulnerable code is
not compiled into any shipped package.
https://security-tracker.debian.org/tracker/CVE-2026-97399