CVE-2026-19499

EUVD-2026-77675
Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.

Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.

At the time of publication, no network-facing application impact is known.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.7 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
glibc
bookworm
postponed
bookworm (security)
vulnerable
forky
vulnerable
sid
2.43-5
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
glibc
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
Fixed 2.39-0ubuntu8.9
released
resolute
Fixed 2.43-2ubuntu2.4
released
xenial
not-affected
eglibc
jammy
dne
noble
dne
resolute
dne
trusty
not-affected