CVE-2026-6368
wordexp with WRDE_APPEND can return or use invalid memory
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
| CWE | CWE-908 |
| Vendor | glibc |
| Product | glibc |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for glibc glibc
Be the first to know when new unknown vulnerabilities affecting glibc glibc are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
glibc / glibc
1.93-260 < 2.43
References
Credits
shinobu