{"id":"SUSE-SU-2026:21780-1","summary":"Security update for glibc","details":"This update for glibc fixes the following issues\n\n- CVE-2026-4046: assertion failure when converting inputs may be used to remotely crash an application (bsc#1261206).\n- CVE-2026-5450: stdio-common: scanf %mc pattern will cause heap overflow when width \u003e 1024 (bsc#1262465).\n- CVE-2026-5928: libio: ungetwc could be used to leak data on special conditions (bsc#1262464).\n","modified":"2026-07-09T18:24:23.726165794Z","published":"2026-05-18T05:17:54Z","related":["CVE-2026-4046","CVE-2026-5450","CVE-2026-5928"],"upstream":["CVE-2026-4046","CVE-2026-5450","CVE-2026-5928"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621780-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261206"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262464"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-4046"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5928"}],"affected":[{"package":{"name":"glibc","ecosystem":"SUSE:Linux Micro Extras 6.2","purl":"pkg:rpm/suse/glibc&distro=SUSE%20Linux%20Micro%20Extras%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.40-160000.5.1"}]}],"ecosystem_specific":{"binaries":[{"glibc-gconv-modules-extra":"2.40-160000.5.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21780-1.json"}}],"schema_version":"1.7.5"}