{"id":"AZL-98042","summary":"CVE-2026-18374 affecting package glibc 2.38-20","details":"Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.\n\n\n\nThis usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.","modified":"2026-08-29T05:27:27Z","published":"2026-08-27T20:17:03Z","upstream":["CVE-2026-18374"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18374"}],"affected":[{"package":{"name":"glibc","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/glibc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.38-20"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-98042.json"}}],"schema_version":"1.9.0"}