CVE-2026-5450
Critical · CVSS 9.8GNU C Library (glibc) — Heap buffer overflow via scanf %mc format width specifier
- CVSS
- 9.8
- nvd
- EPSS
- 0.45%
- 36th pct
- KEV
- No
- Class
- oss containerizable
- CWE-122, CWE-787
Description
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.
Search profile — drives PoC discovery
Symbols scanfsscanffscanfvscanfvsscanfvfscanf%mcmalloc'd character matchformat width specifier__isoc99_scanf__scanf_internalstr_fmtreadread_int
Keywords CVE-2026-5450glibc scanf %mc heap overflowGNU C Library scanf malloc character matchglibc CWE-122 CWE-787glibc 2.7 2.43 scanf buffer overflowscanf format width specifier one byte heap overflowglibc scanf pocglibc scanf exploit
Versions: 2.7 to 2.43
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-15T00:30:20.000Z