Hi, The following vulnerability was published for glibc. CVE-2026-5928[0]: | Calling the ungetwc function on a FILE stream with wide characters | encoded in a character set that has overlaps between its single byte | and multi-byte character encodings, in the GNU C Library version | 2.43 or earlier, may result in an attempt to read bytes before an | allocated buffer, potentially resulting in unintentional disclosure | of neighboring data in the heap, or a program crash. A bug in the | wide character pushback implementation (_IO_wdefault_pbackfail in | libio/wgenops.c) causes ungetwc() to operate on the regular | character buffer (fp->_IO_read_ptr) instead of the actual wide- | stream read pointer (fp->_wide_data->_IO_read_ptr). The program | crash may happen in cases where fp->_IO_read_ptr is not initialized | and hence points to NULL. The buffer under-read requires a special | situation where the input character encoding is such that there are | overlaps between single byte representations and multibyte | representations in that encoding, resulting in spurious matches. The | spurious match case is not possible in the standard Unicode | character sets. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-5928 https://www.cve.org/CVERecord?id=CVE-2026-5928 [1] https://sourceware.org/bugzilla/show_bug.cgi?id=33998 [2] https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0010 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1134544 in glibc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/glibc-team/glibc/-/commit/0e7fede9e9cc122586297bcfc11cd854b8fc1450 ------------------------------------------------------------------------ debian/patches/git-updates.diff: update from upstream stable branch: * debian/patches/git-updates.diff: update from upstream stable branch: - Fix buffer overflow in scanf %mc (CVE-2026-5450). Closes: #1134543. - Fix ungetwc operating on byte stream (CVE-2026-5928). Closes: #1134544. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1134544
Hello, Bug #1134544 in glibc reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/glibc-team/glibc/-/commit/0e7fede9e9cc122586297bcfc11cd854b8fc1450 ------------------------------------------------------------------------ debian/patches/git-updates.diff: update from upstream stable branch: * debian/patches/git-updates.diff: update from upstream stable branch: - Fix buffer overflow in scanf %mc (CVE-2026-5450). Closes: #1134543. - Fix ungetwc operating on byte stream (CVE-2026-5928). Closes: #1134544. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1134544
We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1134544@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 18 Jun 2026 21:48:16 +0200
Source: glibc
Architecture: source
Version: 2.42-17
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Closes: 1133139 1134543 1134544
Changes:
glibc (2.42-17) unstable; urgency=medium
.
[ Aurelien Jarno ]
* debian/patches/git-updates.diff: update from upstream stable branch:
- Fix buffer overflow in scanf %mc (CVE-2026-5450). Closes: #1134543.
- Fix ungetwc operating on byte stream (CVE-2026-5928). Closes: #1134544.
- Save/restore VFP registers inPLT trampolines on arm. Closes: #1133139.
- Suppress iconv intermediate errors with //TRANSLIT.
- debian/patches/hurd-i386/git-run-iconv-test.sh.diff: rebased.
* debian/rules.d/build.mk: append extra_cflags to CFLAGS and ASFLAGS.
* debian/control.in/libc: stop suggesting libnss-nisplus.
* debian/debhelper.in/libc-bin.lintian-overrides: add a
statically-linked-binary override for the ldconfig binary.
* debian/control.in/main: build-depends on libselinux-dev instead of
libselinux1-dev.
.
[ Miao Wang ]
* debian/libc6.symbols.loong64: add.
.
[ Samuel Thibault ]
* debian/patches/hurd-i386/git-SO_TIMESTAMP.diff: Add SO_TIMESTAMP macro.
Checksums-Sha1:
853c76d4926af85e1eb47cfadf665e3d6cd3cbaf 8575 glibc_2.42-17.dsc
ae0e7f2dd7f1ef10f9847c9e93532044a5e95acf 447488 glibc_2.42-17.debian.tar.xz
b32f8e34e86d37e31f82938ecae9eb114e70b05e 9474 glibc_2.42-17_source.buildinfo
Checksums-Sha256:
d004ab83368dec1f86aec110d13d1eaf21b261416e5f7c74f18c8b9ce2d02b79 8575 glibc_2.42-17.dsc
89b79a67661b89a4160ef1b2f01a1eb7b428c686f18de463581b408ba9765e62 447488 glibc_2.42-17.debian.tar.xz
d1720e1efee2058a8c307845a71a549cc5c4281b3df55b6c23e17726ea9777eb 9474 glibc_2.42-17_source.buildinfo
Files:
59ba9441424493ab42de86e0cb47af8d 8575 libs required glibc_2.42-17.dsc
fc88b43e4437d8388a5e79558d3243b8 447488 libs required glibc_2.42-17.debian.tar.xz
7b6a7870542517c4b89f316ac9ce5619 9474 libs required glibc_2.42-17_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmo0TCQACgkQE4jA+Jno
M2vCUw/+OKPA4+V6kCy4U86/X/rBzhA7G+ZRvYSaoBDfP8B8h+UDSXq3N4MmVKPx
hWAVtpzOiFo/aKmiy6DGKKdM6Wb50TZ0vvx+07c4sNAVpQh5ZR+MrbPvP82jNG2o
t7qP4VqVEToMSflhRYwBR+pMOazy5C+Mw71r7aAkDOiqhos4lgFutvNGOX3bVuts
UPuWND2S/KCMn9qgUp3bnlfYK/OXArQzH4MBYjGB3uHOXGg+xLKWPZQO39ufAGKA
m3GbgfCneO/dVp0qzCQeCdjZ5e3gvqR/GfKPRq59/9Zr58nq3bji1zyKfiMb7UxG
I7chnsOeL2k1SN8+b/mg0RpCWbeMGXdSRfIL39KBxypvGt+rRxlWpqcNYBlZuVaI
nhqBPjOSbz5Ox7QjZdVhpaojt9yxWk+Is+0hZrl1mkxIC4qang821KuW3d8UGjua
vTkGhKZGjYqcSsSpQs+iuOxaX4I/QsDnTNHv8MT9zG3HaYazSO8Fqh/lorjJySms
hUhIbpIBWkhqYgZcZKVNWQKjGaUwHZpCjdfYsON5OLMV/MvXAfFkokZMQFpr9A0x
9E/MqFPvckZWAGvaXSwAylDLyUCdMF6mHfHCHJd8m3c4Y66uJKSA27YbSwIsRwAH
7ZEm07fOR1eUF7CcocGvapnRsXCLpErc9tUOs2itNUsiBcQKHKo=
=kmrf
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1134544@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 29 Jun 2026 23:37:52 +0200
Source: glibc
Architecture: source
Version: 2.41-12+deb13u4
Distribution: trixie
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Closes: 1134543 1134544 1135405
Changes:
glibc (2.41-12+deb13u4) trixie; urgency=medium
.
* debian/patches/git-updates.diff: update from upstream stable branch:
- Fix build against linux 7.0 headers. Closes: #1135405.
- Fix ungetwc operating on byte stream (CVE-2026-5928). Closes: #1134544.
- Fix buffer overflow in scanf %mc (CVE-2026-5450). Closes: #1134543.
- Suppress iconv intermediate errors with //TRANSLIT.
Checksums-Sha1:
f291d4082eef7e094241a1a87585f275cf336149 7576 glibc_2.41-12+deb13u4.dsc
57751ec678751a3cf5bf3badb54f6ab6b9760eea 499524 glibc_2.41-12+deb13u4.debian.tar.xz
62b4c5a63a1ea4ff036ac1a3a9ca6e49c7c3d7b9 9744 glibc_2.41-12+deb13u4_source.buildinfo
Checksums-Sha256:
0915324aa646bb99abfaa9aa6ecb734b30babd28454a3e51f3152912370fbd3e 7576 glibc_2.41-12+deb13u4.dsc
dda4153511bfd543502d18e5bc9323110996fe9c531f14ae3fad6eb17f027c7d 499524 glibc_2.41-12+deb13u4.debian.tar.xz
43a8726930a9a9e5f1cdf431c3a239dab03ec5a555acc85d2f5d5c1388f11710 9744 glibc_2.41-12+deb13u4_source.buildinfo
Files:
fa18f1bcbca0299c1ea024bfc9623f7a 7576 libs required glibc_2.41-12+deb13u4.dsc
8e44b0a9913a886a781d99125209f7df 499524 libs required glibc_2.41-12+deb13u4.debian.tar.xz
f005e6cb9bc0bb82a20cf2cb96c14f54 9744 libs required glibc_2.41-12+deb13u4_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmpEnF8ACgkQE4jA+Jno
M2uNMQ/9G6Ez7CakRZfrcoMwH8BBU61EBIYGYav1d74Blw6TWYd0KKmSOQN6dZfr
nbDaWmByx7kKhdxbCjI44y+4GlHPu36CbweSJBhbQi3j/CRS4qP6sjJL7/kAz+gp
Ft1uaHmBJJsaygriQxfojgMXp7NuQ0MAIALwRopKgvRyhkCRxOhqiFwYws3K8TuB
VZ/ywaWRuc1EbiO8KPeUN6HEg9Tq7vHcgcwWfR+rSTMOhVFSzSca4GJI98Q/9kU8
nLx4lyboadzir/PkjI/2BTRCLASW7pFmIZBoYzF5tCrvCNXOGQe34BVnrDzR3f4H
RV1sDHb2oGNRmwqmX8OmY2+/HJGapwmlvcqawlZ7AKo6UxwmfvQHqkwAtZcqgta1
8imlcEjYcZ5GtIxdIS59yScYos8hYtLuOmxXMtZryTaEQzpsb94jKwlQiWfLukaR
9fMkRmaUVrW+bYePjA8oYidIbDX6o0J7TKrQbSvxXqZ6Zfk3nlAqwgPbm0qPrQ+Y
DBYGy6yL+AcWDWb/mNciGfcPu5mqsbHD6O+ciwGu2lQn5TwoGassF7qGecj49eY9
OXoK4FVyNJ6TseC94MwBB1rVzUhk5LUXmsODh0K1qZMyFxr7GAA/TG1YW3k8gTXG
FsxFEFTOMazBGtjH8urnHZ4I0G4NyUAKVqkeTCEfmhUAOtIY/Gg=
=IKe1
-----END PGP SIGNATURE-----