🔐 CVE Alert

CVE-2026-6368

UNKNOWN 0.0

wordexp with WRDE_APPEND can return or use invalid memory

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CWE CWE-908
Vendor glibc
Product glibc
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for glibc glibc

Be the first to know when new unknown vulnerabilities affecting glibc glibc are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

glibc / glibc
1.93-260 < 2.43

References

NVD ↗ CVE.org ↗ EPSS Data ↗
sourceware.org: https://sourceware.org/bugzilla/show_bug.cgi?id=34090 sourceware.org: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014;h=1e9a0039f07471ddfe6816e5df04875bec409f92;hb=HEAD

Credits

shinobu