Description
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.

This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.
Published: 2026-09-28
Score: 3.7 Low
EPSS: n/a
KEV: No
Impact: Denial of Service (Crash)
Action: Apply Patch
AI Analysis

Impact

A one‑byte memory overread can occur in the strncasecmp function when it is optimized for the Power8 architecture. The function may read past the end of the supplied strings by one byte, which can trigger a program crash if the out‑of‑bounds byte lies in unmapped or unreadable memory. This flaw may be exploited when an attacker can supply controlled strings to strncasecmp, causing the application to terminate unexpectedly.

Affected Systems

The vulnerability affects the GNU C Library (glibc) starting with version 2.24 and all later releases that include the Power8‑optimized code path. Only deployments running glibc 2.24 or newer on Power8 processors are susceptible; other architectures and older glibc versions are unaffected.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity; the flaw only yields a denial of service by crashing the process and does not provide direct information disclosure or privilege escalation. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited active exploitation. The likely attack vector is an application that accepts attacker‑controlled input into strncasecmp on a Power8 system, possibly over a network or local interface. Given the low severity and lack of exploitation evidence, the risk remains modest, but the crash can disrupt service availability.

Generated by OpenCVE AI on September 28, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade glibc to a release where the Power8 strncasecmp overread has been fixed.
  • Validate or sanitize any strings passed to strncasecmp so that attacker‑controlled data cannot reach the vulnerable function.
  • Monitor for unexpected process crashes or memory access violations and apply any available patch or backport promptly.

Generated by OpenCVE AI on September 28, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared The Gnu C Library
The Gnu C Library glibc
Vendors & Products The Gnu C Library
The Gnu C Library glibc

Mon, 28 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.
Title One-byte overread in strncasecmp on Power8
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

The Gnu C Library Glibc
cve-icon MITRE

Status: PUBLISHED

Assigner: glibc

Published:

Updated: 2026-09-28T17:07:36.744Z

Reserved: 2026-09-24T14:30:14.230Z

Link: CVE-2026-97399

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:12.843Z

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:18.550

Modified: 2026-09-28T17:17:53.643

Link: CVE-2026-97399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:00:05Z

Weaknesses