OVERVIEW CVE-2026-5928 is a buffer under-read vulnerability in the GNU C Library version 2.43 and earlier affecting the ungetwc() function's wide character pushback implementation. The vulnerability occurs when processing FILE streams with wide characters in encodings that contain overlaps between single-byte and multi-byte character representations. A bug in the _IO_wdefault_pbackfail function causes the implementation to operate on the incorrect buffer pointer, potentially leading to heap data disclosure or application crashes. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network attack vector, low complexity, and no privilege or user interaction required. The primary impact is availability disruption through program crashes, with a secondary risk of information disclosure through heap memory leaks. The potential for unintentional exposure of sensitive neighboring heap data elevates the threat, though exploitation requires specific character encoding conditions with overlapping multi-byte representations, limiting practical attack scenarios in standard Unicode environments. EXPLOITATION STATUS There is no current evidence of active exploitation, as the vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 0.0004 indicates minimal probability of exploitation in the wild, and the vulnerability remains on the inactive Hot List status. Community attention appears limited given the specialized technical requirements and encoding constraints necessary to trigger the vulnerability in production systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.43CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | ||
>= 2.1.1-89, <= 2.43CPE match | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.