Impact
The caller-supplied buffer can be overrun when strfmon or strfmon_l in glibc 2.38-2.44 use right-justified width padding. The overflow requires a format string that forces the function to place data into a buffer that is large enough for the padding yet too small for the internal memmove, allowing an attacker-controlled format string or a fixed vulnerable pattern to corrupt memory. This classic buffer overflow can subvert program control or corrupt data, potentially leading to arbitrary code execution. No network-facing impact has been reported at the time of publication.
Affected Systems
All systems that ship the GNU C Library between version 2.38 and 2.44 are potentially affected. This includes many Linux distributions that have not applied the patch in their current glibc release. The vulnerability is limited to glibc itself; any application that uses these functions under the specified versions could be vulnerable if it passes unchecked format strings to them.
Risk and Exploitability
The CVSS score of 7.7 indicates a high-medium severity. The EPSS score of <1% and absence from the CISA KEV catalog imply a low probability of publicly known exploitation. The vulnerability is triggered by a forced format string code path, meaning a local or privileged attacker who can influence the format string and buffer size has the most straightforward attack vector. While no network-facing impact is documented, a remote attacker could potentially inject the input via a network-driven code path. The risk is concentrated in applications that directly invoke strfmon or strfmon_l with unchecked width padding.
OpenCVE Enrichment
Ubuntu USN