{"id":"CVE-2017-17426","details":"The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an object whose size is close to SIZE_MAX, potentially leading to a subsequent heap overflow. This occurs because the per-thread cache (aka tcache) feature enables a code path that lacks an integer overflow check.","modified":"2026-08-30T14:04:13.392576Z","published":"2017-12-05T17:29:00.940Z","related":["openSUSE-SU-2024:10792-1"],"references":[{"type":"WEB","url":"https://sourceware.org/git/gitweb.cgi?p=glibc.git%3Bh=34697694e8a93b325b18f25f7dcded55d6baeaf6"},{"type":"REPORT","url":"https://sourceware.org/bugzilla/show_bug.cgi?id=22375"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bminor/glibc","events":[{"introduced":"1c9a5c270d8b66f30dcfaf1cb2d6cf39d3e18369"},{"last_affected":"1c9a5c270d8b66f30dcfaf1cb2d6cf39d3e18369"}],"database_specific":{"cpe":"cpe:2.3:a:gnu:glibc:2.26:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.26"},{"last_affected":"2.26"}],"source":"CPE_STRING"}}],"versions":["2.26","glibc-2.26"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17426.json"}},{"ranges":[{"type":"GIT","repo":"https://sourceware.org/git/glibc.git","events":[{"introduced":"1c9a5c270d8b66f30dcfaf1cb2d6cf39d3e18369"},{"last_affected":"1c9a5c270d8b66f30dcfaf1cb2d6cf39d3e18369"}],"database_specific":{"cpe":"cpe:2.3:a:gnu:glibc:2.26:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.26"},{"last_affected":"2.26"}],"source":"CPE_STRING"}}],"versions":["2.26","glibc-2.26"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17426.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}