Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu glibc |
|
| Vendors & Products |
Gnu
Gnu glibc |
Mon, 10 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. | |
| Title | wordexp with WRDE_APPEND can return or use invalid memory | |
| Weaknesses | CWE-908 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: glibc
Published:
Updated: 2026-08-10T18:40:11.601Z
Reserved: 2026-04-15T15:07:08.926Z
Link: CVE-2026-6368
No data.
Status : Received
Published: 2026-08-10T19:17:30.713
Modified: 2026-08-10T19:17:30.713
Link: CVE-2026-6368
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:22:11Z
Weaknesses