CVE-2026-3904

EUVD-2026-11160
Calling NSS-backed functions that support caching via nscd may call the 
nscd client side code and in the GNU C Library version 2.36 under high 
load on x86_64 systems, the client may call memcmp on inputs that are 
concurrently modified by other processes or threads and crash.




The nscd client in the GNU C Library uses the memcmp function with 
inputs that may be concurrently modified by another thread, potentially 
resulting in spurious cache misses, which in itself is not a security 
issue.  However in the GNU C Library version 2.36 an optimized 
implementation of memcmp was introduced for x86_64 which could crash 
when invoked with such undefined behaviour, turning this into a 
potential crash of the nscd client and the application that uses it. 
This implementation was backported to the 2.35 branch, making the nscd 
client in that branch vulnerable as well.  Subsequently, the fix for 
this issue was backported to all vulnerable branches in the GNU C 
Library repository.


It is advised that distributions that may have cherry-picked the memcpy 
SSE2 optimization in their copy of the GNU C Library, also apply the fix 
to avoid the potential crash in the nscd client.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.2 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Affected Products (NVD)
VendorProductVersion
gnuglibc
2.35 ≤
𝑥
< 2.37
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
V3.1.5 ≤
𝑥
< V3.1.6
ADP
SiemensSIMATIC S7-1500 CPU 1518-4 PN/DP MFP
V3.1.5 ≤
𝑥
< V3.1.6
ADP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
V3.1.5 ≤
𝑥
< V3.1.6
ADP
SiemensSIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
V3.1.5 ≤
𝑥
< V3.1.6
ADP
SiemensSIPLUS S7-1500 CPU 1518-4 PN/DP MFP
V3.1.5 ≤
𝑥
< V3.1.6
ADP
Debian logo
Debian Releases
Debian Product
Codename
glibc
bookworm
2.36-9+deb12u14
fixed
bookworm (security)
2.36-9+deb12u7
fixed
bullseye
2.31-13+deb11u11
fixed
bullseye (security)
2.31-13+deb11u14
fixed
forky
2.42-17
fixed
sid
2.42-17
fixed
trixie
2.41-12+deb13u3
fixed