CVE-2017-15671: GNU Glibc

Medium severity, CVSS 5.9. EPSS: 1.4% chance of exploitation in the next 30 days.

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).

Affected products

  • GNU Glibc: up to and including 2.26

Published 2017-10-20. Last modified 2026-06-17.