Home / mailingsPDF  

[USN-8611-1] GNU C Library vulnerabilities

Posted on 27 July 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8611-1
July 27, 2026

glibc vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in GNU C Library.

Software Description:
- glibc: GNU C Library

Details:

It was discovered that the GNU C Library iconv function incorrectly handled
certain IBM character sets. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-4046)

It was discovered that the GNU C Library DNS functions incorrectly handled
certain DNS server responses when using gethostbyaddr or gethostbyaddr_r.
An attacker in a privileged network position could possibly use this issue
to cause an application to violate DNS specification or obtain incorrect
hostname information. This issue only affected Ubuntu 24.04 LTS.
(CVE-2026-4437, CVE-2026-4438)

It was discovered that the GNU C Library deprecated debugging functions
incorrectly enforced caller-supplied buffer lengths. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2026-5435)

It was discovered that the GNU C Library scanf family of functions
contained a heap buffer overflow when processing certain format specifiers.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-5450)

It was discovered that the GNU C Library ungetwc function incorrectly
handled certain character encodings. An attacker could possibly use this
issue to obtain sensitive information or cause a denial of service.
(CVE-2026-5928)

It was discovered that the GNU C Library deprecated debugging functions
incorrectly validated DNS response record data. An attacker could possibly
use this issue to cause a denial of service or obtain sensitive
information. (CVE-2026-6238)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libc6 2.43-2ubuntu2.3

Ubuntu 24.04 LTS
libc6 2.39-0ubuntu8.8

Ubuntu 22.04 LTS
libc6 2.35-0ubuntu3.14

After a standard system update you need to reboot your computer to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8611-1
CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5435,
CVE-2026-5450, CVE-2026-5928, CVE-2026-6238

Package Information:
https://launchpad.net/ubuntu/+source/glibc/2.43-2ubuntu2.3
https://launchpad.net/ubuntu/+source/glibc/2.39-0ubuntu8.8
https://launchpad.net/ubuntu/+source/glibc/2.35-0ubuntu3.14

--===============4293353242875780892==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP