libc bug can crash services

Published September 11, 2026

libc has a CERT-Bund advisory for CVE-2026-4046 in versions through 2.43. A remote, anonymous attacker can exploit a vulnerability in GNU libc to conduct a denial of service attack.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affected versions
through 2.43
Affects
libc+1 more
Exploited
Not confirmedNo confirmation recorded

How it works

A remote, anonymous attacker can exploit a vulnerability in GNU libc to conduct a denial of service attack.

What to do

Check whether you run libc on a system covered by the CERT-Bund advisory.

Apply the vendor security update for libc.

Technical details

Affected software: libc, UNIX

A remote, anonymous attacker can exploit a vulnerability in GNU libc to conduct a denial of service attack. The advisory tracks CVE-2026-4046. In CERT-Bund's CSAF data, affected versions are through 2.43. Affected operating systems listed by CERT-Bund: UNIX.

References