CVE-2026-3904 describes a crash vulnerability in the GNU C Library (glibc) versions 2.36 and 2.35 on x86_64 systems. Under high load, the nscd client, when calling NSS-backed functions, can crash due to an optimized memcmp implementation encountering concurrently modified inputs. This local vulnerability is rated Medium (CVSS 6.2), with low attack complexity, primarily impacting system availability by causing the nscd client and dependent applications to crash. There is no evidence of active exploitation, public exploit code availability, or significant community attention for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.35, < 2.37CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.