Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN863 _____________________________________________________________________ DATE : 28/08/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running GNU C Library versions up to and including 2.45. ===================================================================== https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015;h=3ea6602399152fbc7a868ebbafde89fce0e06397;hb=HEAD _____________________________________________________________________ Buffer overflow in fopen mode argument processing Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU or Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation. CVE-Id: CVE-2026-18374 Public-Date: 2026-08-27 Vulnerable-Commit: 129d706d77587e4d6627cc1ebef9be0f7cbc65f0 Reported-by: AISLE in partnership with Red Hat CVSS: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L - 4.9 ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================