Description
Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.

Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.

At the time of publication, no network-facing application impact is known.
Published: 2026-09-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Code Execution
Action: Immediate Patch
AI Analysis

Impact

The caller-supplied buffer can be overrun when strfmon or strfmon_l in glibc 2.38-2.44 use right-justified width padding. The overflow requires a format string that forces the function to place data into a buffer that is large enough for the padding yet too small for the internal memmove, allowing an attacker-controlled format string or a fixed vulnerable pattern to corrupt memory. This classic buffer overflow can subvert program control or corrupt data, potentially leading to arbitrary code execution. No network-facing impact has been reported at the time of publication.

Affected Systems

All systems that ship the GNU C Library between version 2.38 and 2.44 are potentially affected. This includes many Linux distributions that have not applied the patch in their current glibc release. The vulnerability is limited to glibc itself; any application that uses these functions under the specified versions could be vulnerable if it passes unchecked format strings to them.

Risk and Exploitability

The CVSS score of 7.7 indicates a high-medium severity. The EPSS score of <1% and absence from the CISA KEV catalog imply a low probability of publicly known exploitation. The vulnerability is triggered by a forced format string code path, meaning a local or privileged attacker who can influence the format string and buffer size has the most straightforward attack vector. While no network-facing impact is documented, a remote attacker could potentially inject the input via a network-driven code path. The risk is concentrated in applications that directly invoke strfmon or strfmon_l with unchecked width padding.

Generated by OpenCVE AI on September 20, 2026 at 23:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade glibc to the latest release that contains the fix, as announced in the distribution’s security advisory.
  • If the update is not available, apply any vendor-provided security update or backport that addresses the vulnerability.
  • Review application code that uses strfmon or strfmon_l and restrict or sanitize untrusted input, removing right-justified width padding or validating format strings before use.

Generated by OpenCVE AI on September 20, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8737-1 GNU C Library vulnerabilities
Ubuntu USN Ubuntu USN USN-8737-2 GNU C Library vulnerabilities
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow when processing right-justified width padding. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts. Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known.
Title glibc: Buffer Overflow in strfmon right-justification padding Buffer overflow in strfmon and strfmon_l right-justification padding
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H'}


Mon, 31 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu glibc
Vendors & Products Gnu
Gnu glibc

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow when processing right-justified width padding. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts.
Title glibc: Buffer Overflow in strfmon right-justification padding
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: glibc

Published:

Updated: 2026-09-14T19:40:43.330Z

Reserved: 2026-08-10T18:42:03.154Z

Link: CVE-2026-19499

cve-icon Vulnrichment

Updated: 2026-09-14T19:40:39.869Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:45.753

Modified: 2026-09-18T18:17:47.257

Link: CVE-2026-19499

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-25T07:32:48Z

Links: CVE-2026-19499 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses