CVE-2026-5928
Last modified
CVE-2026-5928 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash. A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | <= 2.43 |
References
- https://sourceware.org/bugzilla/show_bug.cgi?id=33998Exploit, Issue Tracking
- https://sourceware.org/bugzilla/show_bug.cgi?id=33998Exploit, Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-5928?
How severe is CVE-2026-5928?
How do I fix CVE-2026-5928?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59274The UnZipTransformer does not limit decompressed entry size …6.5
- CVE-2026-59275A single hostile AMQP message can terminate the entire consu…4.9
- CVE-2026-59276Several components in Spring Security compare security-sensi…5.9
- CVE-2026-59277Spring Security's InetAddressMatchers utility provides match…5.3
- CVE-2026-59278JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include j…6.5
- CVE-2026-59279The MCP Streamable HTTP server transport (WebFlux and WebMvc…7.5
- CVE-2026-59280Applications using Spring Framework's FreeMarker integration…4.3
- CVE-2026-59281Spring MVC and WebFlux applications that obtain a data-bindi…6.1
- CVE-2026-59282Spring Framework applications that use Spring's data binding…7.5
- CVE-2026-59283Applications that evaluate Spring Expression Language (SpEL)…9.1
- CVE-2026-59284There is no allow list for property keys when Spring Cloud C…7.6
- CVE-2026-59285Spring for GraphQL applications are vulnerable to Unsafe Des…8.1
Are you affected by CVE-2026-5928?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
