Updated glibc packages fix security vulnerabilities
Publication date: 27 Jan 2026Modification date: 27 Jan 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-0861 , CVE-2026-0915 , CVE-2025-15281
Description
Integer overflow in memalign leads to heap corruption. (CVE-2026-0861)
getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler.
(CVE-2026-0915)
wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory.
(CVE-2025-15281)
References
- https://bugs.mageia.org/show_bug.cgi?id=35036
- https://www.openwall.com/lists/oss-security/2026/01/16/5
- https://www.openwall.com/lists/oss-security/2026/01/16/6
- https://www.openwall.com/lists/oss-security/2026/01/20/3
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0861
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-0915
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15281
SRPMS
9/core
- glibc-2.36-59.mga9