Updated glibc package fixes security vulnerabilities
Publication date: 11 Sep 2026Modification date: 11 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-5435 , CVE-2026-6238 , CVE-2026-6368 , CVE-2026-6791 , CVE-2026-19499 , CVE-2026-77117 , CVE-2026-80489
Description
Potential buffer overflow in ns_sprintrrf TSIG handling path.
(CVE-2026-5435)
Buffer overread in ns_printrrf with corrupted RDATA field.
(CVE-2026-6238)
wordexp with WRDE_APPEND can return or use invalid memory.
(CVE-2026-6368)
Potential stack-based buffer clash during tilde expansion in wordexp.
(CVE-2026-6791)
Fix right-justification in strfmon. (CVE-2026-19499)
SHIFT_JISX0213 decoding lacks pending character reset. (CVE-2026-77117)
EUC_JISX0213 decoding lacks pending character reset. (CVE-2026-80489)
References
- https://bugs.mageia.org/show_bug.cgi?id=35262
- https://www.openwall.com/lists/oss-security/2026/04/28/16
- https://www.openwall.com/lists/oss-security/2026/08/11/3
- https://www.cve.org/CVERecord?id=CVE-2026-5435
- https://www.cve.org/CVERecord?id=CVE-2026-6238
- https://www.cve.org/CVERecord?id=CVE-2026-6368
- https://www.cve.org/CVERecord?id=CVE-2026-6791
- https://www.cve.org/CVERecord?id=CVE-2026-19499
- https://www.cve.org/CVERecord?id=CVE-2026-77117
- https://www.cve.org/CVERecord?id=CVE-2026-80489
SRPMS
10/core
- glibc-2.42-10.mga10