CVE-2026-5450: GNU Glibc
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.
Affected products
- GNU Glibc: from 2.7, up to and including 2.43
Published 2026-04-20. Last modified 2026-07-14.