Home / mailingsPDF  

[USN-8737-2] GNU C Library vulnerabilities

Posted on 10 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8737-2
September 10, 2026

glibc vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS

Summary:

Several security issues were fixed in GNU C Library.

Software Description:
- glibc: GNU C Library

Details:

USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides
the corresponding fixes for Ubuntu 24.04 LTS.

Original advisory details:

It was discovered that GNU C Library had a buffer overflow in the strfmon
function when handling right-justification padding. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499)

It was discovered that GNU C Library had an out-of-bounds stack array
access in the tdelete function. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2026-19542)

It was discovered that GNU C Library incorrectly handled memory when
calling wordexp with the WRDE_APPEND flag. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-6368)

It was discovered that GNU C Library had a stack overflow in the wordexp
function when expanding paths beginning with a tilde followed by a long
username. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-6791)

It was discovered that GNU C Library had a hang in the SHIFT_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-77117)

It was discovered that GNU C Library had a hang in the EUC_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-80489)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
libc6 2.39-0ubuntu8.9

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8737-2
https://ubuntu.com/security/notices/USN-8737-1
CVE-2026-19499, CVE-2026-19542, CVE-2026-6368, CVE-2026-6791,
CVE-2026-77117, CVE-2026-80489

Package Information:
https://launchpad.net/ubuntu/+source/glibc/2.39-0ubuntu8.9

--===============5573885466855707030==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP