CVE-2026-0861 is a heap corruption vulnerability in GNU C Library (glibc) versions 2.30 to 2.42, stemming from an integer overflow when passing excessively large alignment values to memalign-suite functions. This vulnerability carries a CVSS score of 8.4 (HIGH), indicating a significant impact with potential for high confidentiality, integrity, and availability compromise, though it requires an attacker to control both size and alignment parameters, making practical exploitation challenging. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage. Community discussion is minimal, with only one mention found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.30, <= 2.42CPE match | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.