libc bug can run code

Published September 11, 2026

libc has a CERT-Bund advisory for 2 vulnerabilities in versions =2.2. A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary code, cause a denial-of-service condition, or disclose sensitive information.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affected versions
2.2 or newer
Affects
libc+1 more
Exploited
Not confirmedNo confirmation recorded

How it works

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary code, cause a denial-of-service condition, or disclose sensitive information.

What to do

Check whether you run libc on a system covered by the CERT-Bund advisory.

Apply the vendor security update for libc.

Technical details

Affected software: libc, UNIX

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary code, cause a denial-of-service condition, or disclose sensitive information. The advisory tracks CVE-2026-5435, CVE-2026-6238. In CERT-Bund's CSAF data, affected versions are =2.2. Affected operating systems listed by CERT-Bund: UNIX.

References