CVE-2026-97399

LOWCVSS 3.7/10

Last modified

CVE-2026-97399 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable..

Description

The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
The GNU C Libraryglibc>= 2.24, < 2.45

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-97399?
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.
How severe is CVE-2026-97399?
CVE-2026-97399 has a CVSS score of 3.7/10 (LOW severity).
How do I fix CVE-2026-97399?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-97399?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST