Memory Access Vulnerability in GNU C Library for Power8 Architecture
CVE-2026-97399
3.7LOW
What is CVE-2026-97399?
The strncasecmp function within the GNU C Library, version 2.24 and newer, contains a flaw that allows for the potential reading of memory beyond the specified input size limit. This issue becomes critical in scenarios where the input strings being passed to strncasecmp can be controlled by an attacker. If these strings are crafted to match exactly to the boundary of their allocated memory page, it can trigger a read from an adjacent memory page that may not be accessible or mapped, leading to application crashes or unpredictable behavior.
Affected Version(s)
glibc Power8 2.24 < 2.45
