Memory Access Vulnerability in GNU C Library for Power8 Architecture
CVE-2026-97399

3.7LOW

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-97399?

The strncasecmp function within the GNU C Library, version 2.24 and newer, contains a flaw that allows for the potential reading of memory beyond the specified input size limit. This issue becomes critical in scenarios where the input strings being passed to strncasecmp can be controlled by an attacker. If these strings are crafted to match exactly to the boundary of their allocated memory page, it can trigger a read from an adjacent memory page that may not be accessible or mapped, leading to application crashes or unpredictable behavior.

Affected Version(s)

glibc Power8 2.24 < 2.45

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AISLE in partnership with Red Hat
.