libc bug can run code
libc has a CERT-Bund advisory for 2 vulnerabilities in versions =2.2. A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary code, cause a denial-of-service condition, or disclose sensitive information.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Not confirmed
- Affected versions
- 2.2 or newer
- Affects
- libc+1 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary code, cause a denial-of-service condition, or disclose sensitive information.
What to do
Check whether you run libc on a system covered by the CERT-Bund advisory.
Apply the vendor security update for libc.
Technical details
Affected software: libc, UNIX
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary code, cause a denial-of-service condition, or disclose sensitive information. The advisory tracks CVE-2026-5435, CVE-2026-6238. In CERT-Bund's CSAF data, affected versions are =2.2. Affected operating systems listed by CERT-Bund: UNIX.
References
- wid.cert-bund.de · wid-sec-w-2026-1300.json technical description
- seclists.org · 251 third party advisory
- github.com · GHSA-h8wx-jcwq-g3cp third party advisory
- bugzilla.redhat.com · show_bug.cgi third party advisory
- sourceware.org · show_bug.cgi third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-4b7780802c third party advisory
- access.redhat.com · RHSA-2026:12740 third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-ced72ab158 third party advisory
- lists.opensuse.org · GQ2A6BC5C5Y4UAZTW2SCWARYRLB5LKRV third party advisory
- lists.opensuse.org · PPUFPVG2PDHIGMI2VUJIOKIZVIJF6W6A third party advisory
- lists.suse.com · 027255.html third party advisory
- lists.suse.com · 027307.html third party advisory
- lists.suse.com · 027400.html third party advisory
- lists.suse.com · 027476.html third party advisory
- lists.suse.com · 027520.html third party advisory
- lists.suse.com · 027519.html third party advisory
- access.redhat.com · RHSA-2026:42694 third party advisory
- errata.build.resf.org · RLSA-2026:42733 third party advisory
- access.redhat.com · RHSA-2026:42733 third party advisory
- access.redhat.com · RHSA-2026:42952 third party advisory
- errata.build.resf.org · RLSA-2026:42952 third party advisory
- linux.oracle.com · ELSA-2026-42952.html third party advisory
- errata.build.resf.org · RLSA-2026:42694 third party advisory
- access.redhat.com · RHSA-2026:44481 third party advisory
- access.redhat.com · RHSA-2026:44624 third party advisory
- ubuntu.com · USN-8611-1 third party advisory
- access.redhat.com · RHSA-2026:46836 third party advisory
- linux.oracle.com · ELSA-2026-42733.html third party advisory
- access.redhat.com · RHSA-2026:48151 third party advisory
- linux.oracle.com · ELSA-2026-500131.html third party advisory
- access.redhat.com · RHSA-2026:50205 third party advisory
- access.redhat.com · RHSA-2026:50847 third party advisory
- access.redhat.com · RHSA-2026:50849 third party advisory
- linux.oracle.com · ELSA-2026-500140.html third party advisory
- access.redhat.com · RHSA-2026:53371 third party advisory
- dell.com · dsa-2026-386-security-update-f third party advisory
- linux.oracle.com · ELSA-2026-42694.html third party advisory
- linux.oracle.com · ELSA-2026-500297.html third party advisory