CVE-2026-5450: GNU Glibc

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Affected products

  • GNU Glibc: from 2.7, up to and including 2.43

Published 2026-04-20. Last modified 2026-07-14.