{"id":"UBUNTU-CVE-2026-19499","details":"Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known.","modified":"2026-09-16T14:01:36.840831141Z","published":"2026-08-27T00:00:00Z","related":["USN-8737-1","USN-8737-2"],"upstream":["CVE-2026-19499"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-19499"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-19499"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8737-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8737-2"}],"affected":[{"package":{"name":"glibc","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/glibc?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.39-0ubuntu8.9"}]}],"versions":["2.38-1ubuntu6","2.38-3ubuntu1","2.39-0ubuntu1","2.39-0ubuntu2","2.39-0ubuntu6","2.39-0ubuntu8","2.39-0ubuntu8.1","2.39-0ubuntu8.2","2.39-0ubuntu8.3","2.39-0ubuntu8.4","2.39-0ubuntu8.5","2.39-0ubuntu8.6","2.39-0ubuntu8.7","2.39-0ubuntu8.8"],"ecosystem_specific":{"binaries":[{"binary_name":"glibc-source","binary_version":"2.39-0ubuntu8.9"},{"binary_name":"libc-bin","binary_version":"2.39-0ubuntu8.9"},{"binary_version":"2.39-0ubuntu8.9","binary_name":"libc-dev-bin"},{"binary_version":"2.39-0ubuntu8.9","binary_name":"libc-devtools"},{"binary_name":"libc6","binary_version":"2.39-0ubuntu8.9"},{"binary_name":"libc6-amd64","binary_version":"2.39-0ubuntu8.9"},{"binary_name":"libc6-dev-amd64","binary_version":"2.39-0ubuntu8.9"},{"binary_name":"libc6-dev-i386","binary_version":"2.39-0ubuntu8.9"},{"binary_version":"2.39-0ubuntu8.9","binary_name":"libc6-dev-s390"},{"binary_version":"2.39-0ubuntu8.9","binary_name":"libc6-dev-x32"},{"binary_version":"2.39-0ubuntu8.9","binary_name":"libc6-i386"},{"binary_name":"libc6-s390","binary_version":"2.39-0ubuntu8.9"},{"binary_name":"libc6-x32","binary_version":"2.39-0ubuntu8.9"},{"binary_name":"locales","binary_version":"2.39-0ubuntu8.9"},{"binary_name":"locales-all","binary_version":"2.39-0ubuntu8.9"},{"binary_version":"2.39-0ubuntu8.9","binary_name":"nscd"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19499.json"}},{"package":{"name":"glibc","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/glibc?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.43-2ubuntu2.4"}]}],"versions":["2.42-0ubuntu3","2.42-2ubuntu1","2.42-2ubuntu2","2.42-2ubuntu4","2.42-2ubuntu5","2.43-2ubuntu1","2.43-2ubuntu2","2.43-2ubuntu2.3"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"2.43-2ubuntu2.4","binary_name":"glibc-source"},{"binary_name":"libc-bin","binary_version":"2.43-2ubuntu2.4"},{"binary_version":"2.43-2ubuntu2.4","binary_name":"libc-dev-bin"},{"binary_name":"libc-devtools","binary_version":"2.43-2ubuntu2.4"},{"binary_version":"2.43-2ubuntu2.4","binary_name":"libc-gconv-modules-extra"},{"binary_name":"libc6","binary_version":"2.43-2ubuntu2.4"},{"binary_name":"libc6-amd64","binary_version":"2.43-2ubuntu2.4"},{"binary_version":"2.43-2ubuntu2.4","binary_name":"libc6-dev-amd64"},{"binary_name":"libc6-dev-i386","binary_version":"2.43-2ubuntu2.4"},{"binary_version":"2.43-2ubuntu2.4","binary_name":"libc6-dev-x32"},{"binary_name":"libc6-i386","binary_version":"2.43-2ubuntu2.4"},{"binary_name":"libc6-x32","binary_version":"2.43-2ubuntu2.4"},{"binary_name":"locales","binary_version":"2.43-2ubuntu2.4"},{"binary_name":"locales-all","binary_version":"2.43-2ubuntu2.4"},{"binary_name":"nscd","binary_version":"2.43-2ubuntu2.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-19499.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]}