Medium severity4.9NVD Advisory· Published Aug 27, 2026
CVE-2026-18374
CVE-2026-18374
Description
Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.
This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for ccs should not pass them through without validation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.45
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.