It was discovered that GNU C Library had a buffer overflow in the strfmon function when handling right-justification padding. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499)
It was discovered that GNU C Library had an out-of-bounds stack array access in the tdelete function. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-19542)
It was discovered that GNU C Library incorrectly handled memory when calling wordexp with the WRDE_APPEND flag. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-6368)
It was discovered that GNU C Library had a stack overflow in the wordexp function when expanding paths beginning with a tilde followed by a long username. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-6791)
It was discovered that GNU C Library had a hang in the SHIFT_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-77117)
It was discovered that GNU C Library had a hang in the EUC_JISX0213 character set converter. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-80489)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "glibc-source",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc-bin",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc-dev-bin",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc-devtools",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-amd64",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-dev-amd64",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-dev-i386",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-dev-s390",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-dev-x32",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-i386",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-prof",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-s390",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "libc6-x32",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "locales",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "locales-all",
"binary_version": "2.35-0ubuntu3.15"
},
{
"binary_name": "nscd",
"binary_version": "2.35-0ubuntu3.15"
}
]
}
{
"cves": [
{
"id": "CVE-2026-6368",
"severity": [
{
"score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:P/AU:Y/U:Green",
"type": "CVSS_V4"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-6791",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U",
"type": "CVSS_V4"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-19542",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-77117",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-80489",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8737-1.json"
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "glibc-source",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc-bin",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc-dev-bin",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc-devtools",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc-gconv-modules-extra",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc6",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc6-amd64",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc6-dev-amd64",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc6-dev-i386",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc6-dev-x32",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc6-i386",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "libc6-x32",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "locales",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "locales-all",
"binary_version": "2.43-2ubuntu2.4"
},
{
"binary_name": "nscd",
"binary_version": "2.43-2ubuntu2.4"
}
]
}
{
"cves": [
{
"id": "CVE-2026-6368",
"severity": [
{
"score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/S:P/AU:Y/U:Green",
"type": "CVSS_V4"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-6791",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U",
"type": "CVSS_V4"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-19499",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-19542",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-77117",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2026-80489",
"severity": [
{
"score": "medium",
"type": "Ubuntu"
}
]
}
],
"ecosystem": "Ubuntu:26.04:LTS"
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8737-1.json"