Skip to main content
Vulnerability Database/CVE-2026-95818

CVE-2026-95818: GNU C Library Buffer Overflow Vulnerability

CVE-2026-95818 is a stack-based buffer overflow in GNU C Library dynamic loader affecting versions 2.14 through 2.44. This critical flaw enables local attackers to crash setuid programs. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-95818 Overview

CVE-2026-95818 is a stack-based buffer overflow [CWE-121] in the dynamic loader (ld.so) of the GNU C Library (glibc), affecting versions 2.14 through 2.44. The flaw allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. The loader mishandles DT_RPATH or DT_RUNPATH entries that begin with $ORIGIN followed by a NUL byte or /. This condition causes the loader to read past the end of the path buffer and write past the end of a stack-allocated internal buffer. Exploitation is limited to local scenarios with high attack complexity.

Critical Impact

Local attackers can trigger loader crashes in privileged binaries and cause limited disclosure of process memory through corruption of the loader stack.

Affected Products

  • GNU C Library (glibc) version 2.14 through 2.44
  • Linux distributions bundling affected glibc releases
  • setuid/setgid binaries linked with DT_RPATH or DT_RUNPATH containing $ORIGIN

Discovery Timeline

  • 2026-09-22 - CVE-2026-95818 published to the National Vulnerability Database
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95818

Vulnerability Analysis

The vulnerability resides in glibc's dynamic loader path expansion logic. When ld.so processes the DT_RPATH or DT_RUNPATH tags embedded in an ELF binary, it expands the $ORIGIN token to the directory containing the executable. The loader assumes the token is followed by additional path components, but supplies no defensive check when the input terminates with a NUL byte or a bare / immediately after $ORIGIN.

During expansion, the loader reads beyond the source path buffer and writes the resulting string into a fixed-size stack buffer. The out-of-bounds write corrupts adjacent stack data belonging to the loader itself, producing a crash or the disclosure of a small amount of process memory. Because the loader executes before main(), corruption occurs during process initialization of any affected binary.

Root Cause

The defect is a boundary check omission in the $ORIGIN substitution routine. The loader computes the substituted string length using assumptions that do not hold when $ORIGIN is the entire path or is followed only by a path separator. Copying the expanded value into the stack-allocated internal buffer exceeds its capacity, matching the pattern of [CWE-121] stack-based buffer overflow.

Attack Vector

An attacker with local access must execute a setuid or setgid binary whose ELF dynamic section contains a DT_RPATH or DT_RUNPATH value beginning with $ORIGIN and terminating with NUL or /. Under the AT_SECURE flag, the loader still processes these tags, so triggering the flaw does not require environment variable manipulation. The bug is exploited during process startup by the vulnerable binary itself, which is why the attack complexity is high — the affected binary must be built with the vulnerable RPATH pattern.

A verified proof-of-concept is not publicly available. Refer to the Sourceware Bug Report #34360 and the Sourceware GLIBC Security Advisory for technical details from the maintainers.

Detection Methods for CVE-2026-95818

Indicators of Compromise

  • Unexpected SIGSEGV or SIGABRT termination of setuid/setgid binaries during process startup, before main() executes.
  • Kernel audit records or dmesg entries citing segmentation faults inside ld-linux.so or ld-2.*.so.
  • Core dumps whose crashing frame is located in glibc dynamic loader routines that expand DT_RPATH or DT_RUNPATH.

Detection Strategies

  • Inventory setuid and setgid binaries on Linux hosts and inspect their dynamic section with readelf -d for RPATH or RUNPATH entries beginning with $ORIGIN and ending in NUL or /.
  • Query installed glibc versions (ldd --version) across the fleet and flag any hosts running versions 2.14 through 2.44.
  • Correlate crash telemetry from privileged binaries with the presence of vulnerable glibc packages to identify likely exploitation attempts.

Monitoring Recommendations

  • Forward Linux audit logs, abrt/systemd-coredump events, and kernel messages to a centralized analytics platform for anomaly review.
  • Alert on repeated loader-stage crashes originating from the same user or the same setuid binary within short intervals.
  • Track glibc package versions as part of continuous configuration monitoring and vulnerability management workflows.

How to Mitigate CVE-2026-95818

Immediate Actions Required

  • Apply distribution-supplied glibc updates that address the loader $ORIGIN expansion flaw as soon as vendor packages are available.
  • Audit all setuid/setgid binaries for DT_RPATH or DT_RUNPATH values starting with $ORIGIN and rebuild affected software without the malformed pattern.
  • Restrict local shell access on multi-user systems to reduce the attacker population able to reach the vulnerable code path.

Patch Information

The glibc maintainers have published guidance in the Sourceware GLIBC Security Advisory and tracked the fix through Sourceware Bug Report #34360. Monitor Linux distribution security trackers for backported glibc packages covering versions 2.14 through 2.44.

Workarounds

  • Remove the setuid/setgid bit from non-essential privileged binaries until patched glibc packages are deployed.
  • Rebuild affected applications so that DT_RPATH and DT_RUNPATH do not begin with $ORIGIN followed by NUL or /, or omit RPATH entirely and rely on system library search paths.
  • Enforce mandatory access controls (SELinux, AppArmor) to constrain what compromised privileged binaries can do if a crash is induced.
bash
# Configuration example
# Enumerate setuid/setgid binaries and inspect their RPATH/RUNPATH entries
find / -xdev \( -perm -4000 -o -perm -2000 \) -type f 2>/dev/null | \
  while read -r bin; do
    rpath=$(readelf -d "$bin" 2>/dev/null | \
      grep -E 'R(PATH|UNPATH)')
    if echo "$rpath" | grep -q '\$ORIGIN'; then
      echo "[REVIEW] $bin -> $rpath"
    fi
  done

# Confirm the installed glibc version
ldd --version | head -n1

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.