Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-19499
Wolfi vulnerability analysis and mitigation

Overview

CVE-2026-19499 is a buffer overflow vulnerability in the GNU C Library (glibc) affecting the strfmon and strfmon_l functions during right-justified width padding processing. An incorrect length is used for an internal memmove operation, causing an out-of-bounds write beyond the intended output buffer. The vulnerability was reported on August 25, 2026, and affects glibc as shipped in Ubuntu 26.04 LTS (and related distributions). It carries a CVSS v3.1 base score of 6.8 (Medium/High) (Red Hat CVE, Red Hat Bugzilla).

Technical details

The root cause is an out-of-bounds write (CWE-787) in glibc's monetary formatting functions strfmon and strfmon_l. When processing right-justified width padding, the code incorrectly uses the post-padding length rather than the correct buffer length when performing an in-place memmove, writing data beyond the caller-supplied output buffer. Exploitation requires a reachable code path that invokes strfmon/strfmon_l with right-justified width padding and a destination buffer large enough for __printf_buffer_pad to succeed but too small for the subsequent overlong memmove — this condition may arise through attacker-influenced format strings or a fixed susceptible formatting pattern in the calling application (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation can lead to denial of service (application crash) or arbitrary code execution, depending on the memory layout at the time of the overflow. The vulnerability has high integrity and availability impact, with low confidentiality impact per the CVSS scoring. Because glibc is a foundational library used by virtually all Linux userspace applications, any application invoking strfmon/strfmon_l with attacker-influenced input could be a vector, though exploitation is constrained to local access with user interaction required (Ubuntu USN-8737-1, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The CVE status remains "Reserved" in the NVD, and there is no indication of inclusion in CISA's Known Exploited Vulnerabilities catalog. Exploitation is limited to local attack vectors and requires user interaction, reducing the overall risk compared to remotely exploitable vulnerabilities. No EPSS score or threat actor attribution is currently available (Red Hat Bugzilla).

Mitigation and workarounds

Ubuntu has released patched glibc packages addressing this vulnerability. Users should update to the following versions: Ubuntu 26.04 LTS — libc6 2.43-2ubuntu2.4; Ubuntu 24.04 LTS — libc6 2.39-0ubuntu8.9; Ubuntu 22.04 LTS — libc6 2.35-0ubuntu3.15. A standard system update (apt update && apt upgrade) will apply the necessary fixes. No specific configuration-based workaround is documented; upgrading is the recommended remediation (Ubuntu USN-8737-1, Ubuntu USN-8737-2).

Community reactions

Coverage has been limited to vendor security advisories and Linux security news aggregators. Ubuntu issued two security notices (USN-8737-1 and USN-8737-2) addressing this and related glibc vulnerabilities, and the issue was noted in Linux security roundup articles. No notable independent researcher commentary or significant social media discussion has been identified (Ubuntu USN-8737-1, Ubuntu USN-8737-2).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

glibc

Affected

sid

glibc: 2.43-5

Fixed

trixie

glibc

Affected

Ubuntu

Fixed

bionic (esm-infra)

glibc

Not Affected

devel

glibc

Unknown

focal (esm-infra)

glibc

Not Affected

jammy

glibc

Not Affected

noble

glibc: 2.39-0ubuntu8.9

Fixed

resolute

glibc: 2.43-2ubuntu2.4

Fixed

trusty (esm-infra-legacy)

eglibc

Not Affected

xenial (esm-infra-legacy)

glibc

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

glibc.src

Affected

SourceThis report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85731HIGH8.8
  • Wolfi logoWolfi
  • oras
NoYesSep 16, 2026
CVE-2026-91964HIGH8.7
  • Wolfi logoWolfi
  • freerdp3
NoYesSep 15, 2026
CVE-2026-91963HIGH7.1
  • Wolfi logoWolfi
  • libwinpr-devel
NoYesSep 15, 2026
CVE-2026-61709MEDIUM5.3
  • Wolfi logoWolfi
  • openfga
NoYesSep 16, 2026
CVE-2026-85732MEDIUM4.7
  • Wolfi logoWolfi
  • oras
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management