CVE-2026-18374
ADVISORY - nistSummary
Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.
This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for ccs should not pass them through without validation.
Common Weakness Enumeration (CWE)
ADVISORY - nist
Out-of-bounds Write
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-18374
EXPLOITABILITY SCORE
1.4
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
4.9mediumDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-18374
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-