CVE-2026-19499

HIGH CVSS 3.1: 7.7 EPSS 0.38%
Updated Sep 14, 2026
Calling
Parameter Value
CVSS 7.7 (HIGH)
Affected Versions 2.38 — 2.44
Type CWE-122 (Heap-based Buffer Overflow)
Vendor Calling
Public PoC No

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.

At the time of publication, no network-facing application impact is known.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
Low
Partial data modification
Availability
High
Complete denial of service

CVSS Vector v3.1