Bug#1134544: glibc: CVE-2026-5928

Salvatore Bonaccorso <[email protected]> Tue, 21 Apr 2026 17:51:37 +0200
Newsgroups gmane.linux.debian.devel.glibc
Message-ID <177678669724.354652.2780233740208690583.reportbug__15213.2310367719$1776786808$gmane$org@eldamar.lan>
Source: glibc
Version: 2.42-15
Severity: important
Tags: security upstream
Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=33998
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for glibc.

CVE-2026-5928[0]:
| Calling the ungetwc function on a FILE stream with wide characters
| encoded in a character set that has overlaps between its single byte
| and multi-byte character encodings, in the GNU C Library version
| 2.43 or earlier, may result in an attempt to read bytes before an
| allocated buffer, potentially resulting in unintentional disclosure
| of neighboring data in the heap, or a program crash.  A bug in the
| wide character pushback implementation (_IO_wdefault_pbackfail in
| libio/wgenops.c) causes ungetwc() to operate on the regular
| character buffer (fp->_IO_read_ptr) instead of the actual wide-
| stream read pointer (fp->_wide_data->_IO_read_ptr). The program
| crash may happen in cases where fp->_IO_read_ptr is not initialized
| and hence points to NULL. The buffer under-read requires a special
| situation where the input character encoding is such that there are
| overlaps between single byte representations and multibyte
| representations in that encoding, resulting in spurious matches. The
| spurious match case is not possible in the standard Unicode
| character sets.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-5928
    https://www.cve.org/CVERecord?id=CVE-2026-5928
[1] https://sourceware.org/bugzilla/show_bug.cgi?id=33998
[2] https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0010

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore