#1146721 glibc: CVE-2026-18374

Package:
src:glibc
Source:
src:glibc
Submitter:
Salvatore Bonaccorso
Date:
2026-09-05 09:21:05 UTC
Severity:
normal
Tags:
#1146721#5
Date:
2026-09-04 18:58:39 UTC
From:
To:
Hi,

The following vulnerability was published for glibc.

CVE-2026-18374[0]:
| Passing an effectively empty string to the `,ccs=` syntax extension
| of the mode argument in the `fopen` function in the GNU C Library
| version 2.45 or earlier may result in a heap buffer overflow when
| the mode string input to the function is attacker controlled.
| This usage pattern is not seen in applications in common GNU/Linux
| distributions and applications that process user-supplied values for
| `ccs` should not pass them through without validation.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-18374
https://www.cve.org/CVERecord?id=CVE-2026-18374
[1] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015

Please adjust the affected versions in the BTS as needed.

Rgards,
Salvatore

#1146721#8
Date:
2026-09-04 22:30:52 UTC
From:
To:
Hello,

Bug #1146721 in glibc reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/glibc-team/glibc/-/commit/e7a9b21145e2ff85cc207df48db75310cc96f378
------------------------------------------------------------------------
debian/patches/git-updates.diff: update from upstream stable branch:

* debian/patches/git-updates.diff: update from upstream stable branch:
  - Fix a heap buffer overlow in how fopen() parses the ,ccs= mode suffix
    (CVE-2026-18374).  Closes: #1146721.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146721

#1146721#13
Date:
2026-09-05 08:49:19 UTC
From:
To:
Hello,

Bug #1146721 in glibc reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/glibc-team/glibc/-/commit/28c14c76b6319d535e009b249be1642763cd7670
------------------------------------------------------------------------
debian/patches/git-updates.diff: update from upstream stable branch:

* debian/patches/git-updates.diff: update from upstream stable branch:
  - Fix a heap buffer overlow in how fopen() parses the ,ccs= mode suffix
    (CVE-2026-18374).  Closes: #1146721.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1146721

#1146721#18
Date:
2026-09-05 09:19:18 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1146721@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 05 Sep 2026 11:01:17 +0200
Source: glibc
Architecture: source
Version: 2.43-5
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Closes: 1145140 1145332 1145406 1145880 1145891 1145987 1146721
Changes:
 glibc (2.43-5) unstable; urgency=medium
 .
   [ Samuel Thibault ]
   * debian/patches/hurd-i386/git-timedblock-signal.diff: Fix livelock of timed
     waits vs signals.
   * debian/patches/hurd-i386/git-time_bits_i386.diff: Warn about compiling
     with _TIME_BITS=64 on hurd-i386.  Closes: #1145140.
   * debian/patches/hurd-i386/git-time_bits_i386_32.diff: Compile programs with
     _TIME_BITS=32 on hurd-i386.
   * debian/patches/hurd-i386/git-setreugid.diff: Fix setreuid/setregid setting
     saved ID to new effective ID.
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
     - Fix unresolvable R_68K_32 relocation against symbol `fmod@@GLIBC_2.43'
       on m68k.  Closes: #1145406.
     - Fix a buffer overflow in strfmon right-justification padding
       (CVE-2026-19499).  Closes: #1145891.
     - Fix a hang when decoding SHIFT_JISX0213 to UTF-32 (CVE-2026-77117).
       Closes: #1145880.
     - Fix a hand when decoding EUC_JISX0213 to UTF-32 (CVE-2026-80489).
       Closes: #1145987.
     - Fix setrlimit compat symbol for negative rlim values besides -1 on
       alpha.
     - Fix stack alignment in makecontext on alpha.
     - Fix FE_NOMASK_ENV on alpha.
     - Mark test-float32x-float64-div as failing on alpha.
     - Fix a heap buffer overlow in how fopen() parses the ,ccs= mode suffix
       (CVE-2026-18374).  Closes: #1146721.
 .
   [ Michael Cree ]
   * Update the expected testsuite failures for alpha.  Closes: #1145332.
Checksums-Sha1:
 50728368d14b4fc1ddf3a59f1ed6fcda3fd8701b 8571 glibc_2.43-5.dsc
 16b0fc62ab0508f17c64c3d0d54d1562c9476be3 488640 glibc_2.43-5.debian.tar.xz
 d00380781cd4827925bd06d3ff52388ad078a4d2 9497 glibc_2.43-5_source.buildinfo
Checksums-Sha256:
 ca7c7966a111971013900f42cd6c164c6ea2c20e10866db26789c1f3520300f7 8571 glibc_2.43-5.dsc
 206a73950742be6fdcfc19d7502acd96bf9b2b4cace0433f076bfa89fbaf4db7 488640 glibc_2.43-5.debian.tar.xz
 eab5c4c9da2819eb666eaf071247458f9e06c2880846b4e2abd0bfde03c64afe 9497 glibc_2.43-5_source.buildinfo
Files:
 e7d5aa300abbd5c110cfb2d72bd6677b 8571 libs required glibc_2.43-5.dsc
 c9abc03d65331e920059b7c39d92a3e1 488640 libs required glibc_2.43-5.debian.tar.xz
 2f91024eae4ea32b2fcaf3ff9ad17e18 9497 libs required glibc_2.43-5_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmqb3AcACgkQE4jA+Jno
M2sqWA//aTmPQtd+9NG8pXXXJQzvrfRh6bwYI3kubftK38KxnR2vq+3x7m0lQOlw
BnN2DQ1ubKcga3aBERzJXEUC1Y1OwCBKkvVuJVM1UMrhRSnKr5jnAY49LePj4gyc
CcM+U49lvKVJOnKjoz3AkIEtM/7o4cQYpqo/Jrc+n7078kDITW63CGmGu6LbuXBx
H0B2vrTE1+XEEWZ7aJlU6MPoz6FrmsHXo4VCgYbn6YEBeYg0+xmmuagLm4jbCVmz
TO4nYX/vRprtU0JuN3ONJ0MaTbrCd8cV+lf6Y0E19XYxLn/vc3gpK5PJEdGKH5EM
qMsU1x6vZvq8b8h9XaOHH2WeA4KJZI6NHuLh4oNLg/9KgNLGf9kL2H1ogIuvS1v4
Xlz+vpOdmp+rVQ2noraBm5bgqqmY5fHLnnfmd8qROJ1l/juKgEc5z4EW3kvfPeDx
MZXRVj3uRUS/trg9/SKQJtXEv8Bl2l5iLlUM73eIsSPQ0qUVQNX95+1eje84degd
WkXHd5uPR2UJIyLHMntxXoIrIEpVKP1xEGIdHhq+By4MM6ch49z+HzH5WAVk1TP2
81A4l1jsIXmxaEncDvnENgJjMms6tFIlLdEEkWh8nHdKDXf11vqxxi9SVFFbAa9Q
zctVElJZE8iXsxu6VW95ile5l9qyA72YTVwCGAogbIYxnhCsfBk=
=7wK7
-----END PGP SIGNATURE-----