CVE-2026-97399
Received Received - Intake

Buffer Overflow in GNU C Library Power8 Optimization

Vulnerability report for CVE-2026-97399, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GNU C Library

Description

The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gnu gnu_c_library 2.24

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the strncasecmp function in the GNU C Library (glibc) version 2.24 and later when optimized for Power8 architecture. It may read one byte beyond the intended input size limit, potentially causing a program crash if that byte is not readable. This occurs when attacker-controlled input strings match up to the edge of their memory page and the adjacent page is inaccessible.

Detection Guidance

This vulnerability is specific to the GNU C Library's strncasecmp function on Power8 architecture. Detection requires checking if your system uses glibc 2.24 or later and Power8 optimizations. No direct network detection commands exist; focus on system library inspection.

Impact Analysis

This vulnerability could cause denial-of-service conditions by crashing programs that use the affected strncasecmp function with attacker-controlled input. It does not lead to data breaches or privilege escalation but may disrupt services relying on glibc functions.

Compliance Impact

This vulnerability primarily impacts availability by causing crashes. It does not directly affect data confidentiality or integrity, so compliance impact depends on whether service disruptions violate availability requirements in GDPR, HIPAA, or other standards.

Mitigation Strategies

Update the GNU C Library to a version that fixes this issue. If using Power8, consider disabling Power8-specific optimizations or applying vendor patches. Monitor glibc updates from your distribution vendor.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97399. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart