๐Ÿ” CVE Alert

CVE-2026-5450

UNKNOWN 0.0

scanf %mc off-by-one heap buffer overflow

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

CWE CWE-122
Vendor the gnu c library
Product glibc
Published Apr 20, 2026
Stay Ahead of the Next One

Get instant alerts for the gnu c library glibc

Be the first to know when new unknown vulnerabilities affecting the gnu c library glibc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The GNU C Library / glibc
2.7 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sourceware.org: https://sourceware.org/bugzilla/show_bug.cgi?id=CVE-2026-5450 inbox.sourceware.org: https://inbox.sourceware.org/libc-announce/[email protected]/T/#u

Credits

Rocket Ma