Home / mailings [USN-8737-1] GNU C Library vulnerabilities
Posted on 08 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8737-1
September 08, 2026
glibc vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in GNU C Library.
Software Description:
- glibc: GNU C Library
Details:
It was discovered that GNU C Library had a buffer overflow in the strfmon
function when handling right-justification padding. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499)
It was discovered that GNU C Library had an out-of-bounds stack array
access in the tdelete function. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2026-19542)
It was discovered that GNU C Library incorrectly handled memory when
calling wordexp with the WRDE_APPEND flag. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-6368)
It was discovered that GNU C Library had a stack overflow in the wordexp
function when expanding paths beginning with a tilde followed by a long
username. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-6791)
It was discovered that GNU C Library had a hang in the SHIFT_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-77117)
It was discovered that GNU C Library had a hang in the EUC_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-80489)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libc6 2.43-2ubuntu2.4
Ubuntu 22.04 LTS
libc6 2.35-0ubuntu3.15
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8737-1
CVE-2026-19499, CVE-2026-19542, CVE-2026-6368, CVE-2026-6791,
CVE-2026-77117, CVE-2026-80489
Package Information:
https://launchpad.net/ubuntu/+source/glibc/2.43-2ubuntu2.4
https://launchpad.net/ubuntu/+source/glibc/2.35-0ubuntu3.15
--===============6517350194371562045==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
