Impact
A one‑byte memory overread can occur in the strncasecmp function when it is optimized for the Power8 architecture. The function may read past the end of the supplied strings by one byte, which can trigger a program crash if the out‑of‑bounds byte lies in unmapped or unreadable memory. This flaw may be exploited when an attacker can supply controlled strings to strncasecmp, causing the application to terminate unexpectedly.
Affected Systems
The vulnerability affects the GNU C Library (glibc) starting with version 2.24 and all later releases that include the Power8‑optimized code path. Only deployments running glibc 2.24 or newer on Power8 processors are susceptible; other architectures and older glibc versions are unaffected.
Risk and Exploitability
The CVSS score of 3.7 indicates low severity; the flaw only yields a denial of service by crashing the process and does not provide direct information disclosure or privilege escalation. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited active exploitation. The likely attack vector is an application that accepts attacker‑controlled input into strncasecmp on a Power8 system, possibly over a network or local interface. Given the low severity and lack of exploitation evidence, the risk remains modest, but the crash can disrupt service availability.
OpenCVE Enrichment