
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19499 is a buffer overflow vulnerability in the GNU C Library (glibc) affecting the strfmon and strfmon_l functions during right-justified width padding processing. An incorrect length is used for an internal memmove operation, causing an out-of-bounds write beyond the intended output buffer. The vulnerability was reported on August 25, 2026, and affects glibc as shipped in Ubuntu 26.04 LTS (and related distributions). It carries a CVSS v3.1 base score of 6.8 (Medium/High) (Red Hat CVE, Red Hat Bugzilla).
The root cause is an out-of-bounds write (CWE-787) in glibc's monetary formatting functions strfmon and strfmon_l. When processing right-justified width padding, the code incorrectly uses the post-padding length rather than the correct buffer length when performing an in-place memmove, writing data beyond the caller-supplied output buffer. Exploitation requires a reachable code path that invokes strfmon/strfmon_l with right-justified width padding and a destination buffer large enough for __printf_buffer_pad to succeed but too small for the subsequent overlong memmove — this condition may arise through attacker-influenced format strings or a fixed susceptible formatting pattern in the calling application (Red Hat Bugzilla, Red Hat CVE).
Successful exploitation can lead to denial of service (application crash) or arbitrary code execution, depending on the memory layout at the time of the overflow. The vulnerability has high integrity and availability impact, with low confidentiality impact per the CVSS scoring. Because glibc is a foundational library used by virtually all Linux userspace applications, any application invoking strfmon/strfmon_l with attacker-influenced input could be a vector, though exploitation is constrained to local access with user interaction required (Ubuntu USN-8737-1, Red Hat CVE).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The CVE status remains "Reserved" in the NVD, and there is no indication of inclusion in CISA's Known Exploited Vulnerabilities catalog. Exploitation is limited to local attack vectors and requires user interaction, reducing the overall risk compared to remotely exploitable vulnerabilities. No EPSS score or threat actor attribution is currently available (Red Hat Bugzilla).
Ubuntu has released patched glibc packages addressing this vulnerability. Users should update to the following versions: Ubuntu 26.04 LTS — libc6 2.43-2ubuntu2.4; Ubuntu 24.04 LTS — libc6 2.39-0ubuntu8.9; Ubuntu 22.04 LTS — libc6 2.35-0ubuntu3.15. A standard system update (apt update && apt upgrade) will apply the necessary fixes. No specific configuration-based workaround is documented; upgrading is the recommended remediation (Ubuntu USN-8737-1, Ubuntu USN-8737-2).
Coverage has been limited to vendor security advisories and Linux security news aggregators. Ubuntu issued two security notices (USN-8737-1 and USN-8737-2) addressing this and related glibc vulnerabilities, and the issue was noted in Linux security roundup articles. No notable independent researcher commentary or significant social media discussion has been identified (Ubuntu USN-8737-1, Ubuntu USN-8737-2).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
glibc
devel
glibc
focal (esm-infra)
glibc
jammy
glibc
noble
glibc: 2.39-0ubuntu8.9
resolute
glibc: 2.43-2ubuntu2.4
trusty (esm-infra-legacy)
eglibc
xenial (esm-infra-legacy)
glibc
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."