CVE-2026-95619: Integer Overflow or Wraparound in Red Hat Red Hat Hardened Images
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
AI Analysis
Technical Summary
This vulnerability arises from an integer overflow in the libstdc++ new operator used in applications compiled with older gcc versions on Red Hat Enterprise Linux 8 and 9. The overflow can cause undersized memory allocations when handling large inputs, potentially resulting in memory corruption or application instability. The flaw is classified under CWE-190 (Integer Overflow or Wraparound) and can lead to denial of service through crashes or resource exhaustion, as well as integrity impacts such as memory modification. Red Hat has published an advisory but currently does not provide an official fix or mitigation that meets their standards for ease of use, applicability, and stability.
Potential Impact
The vulnerability can cause undersized memory allocations, leading to memory corruption or application instability. This may result in denial of service conditions such as crashes or resource exhaustion. Integrity of applications may be compromised due to memory modification. The CVSS v3.1 score is 7.7 (high), reflecting network attack vector with high complexity and no privileges or user interaction required. Confidentiality impact is low, but integrity and availability impacts are high.
Mitigation Recommendations
Red Hat currently does not offer an official fix or mitigation that meets their product security criteria for ease of use, deployment, applicability, or stability. Users are advised to monitor Red Hat's advisory page for updates. Upgrading to supported product versions that include a fix, once available, is recommended. Customers with Red Hat Technical Account Managers (TAM) can consult directly for guidance. No temporary or partial mitigations are currently endorsed by Red Hat.
CVE-2026-95619: Integer Overflow or Wraparound in Red Hat Red Hat Hardened Images
Description
A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corruption or application instability.
CVSS v3.1
Score 7.7high
Affected software
Red Hat
Red Hat Hardened Images
Red Hat
Red Hat Hardened Images
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 6
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat OpenShift Container Platform 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from an integer overflow in the libstdc++ new operator used in applications compiled with older gcc versions on Red Hat Enterprise Linux 8 and 9. The overflow can cause undersized memory allocations when handling large inputs, potentially resulting in memory corruption or application instability. The flaw is classified under CWE-190 (Integer Overflow or Wraparound) and can lead to denial of service through crashes or resource exhaustion, as well as integrity impacts such as memory modification. Red Hat has published an advisory but currently does not provide an official fix or mitigation that meets their standards for ease of use, applicability, and stability.
Potential Impact
The vulnerability can cause undersized memory allocations, leading to memory corruption or application instability. This may result in denial of service conditions such as crashes or resource exhaustion. Integrity of applications may be compromised due to memory modification. The CVSS v3.1 score is 7.7 (high), reflecting network attack vector with high complexity and no privileges or user interaction required. Confidentiality impact is low, but integrity and availability impacts are high.
Mitigation Recommendations
Red Hat currently does not offer an official fix or mitigation that meets their product security criteria for ease of use, deployment, applicability, or stability. Users are advised to monitor Red Hat's advisory page for updates. Upgrading to supported product versions that include a fix, once available, is recommended. Customers with Red Hat Technical Account Managers (TAM) can consult directly for guidance. No temporary or partial mitigations are currently endorsed by Red Hat.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-22T10:25:12.951Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-95619","vendor":"Red Hat"}]
Threat ID: 6ab27ca4f7a7c5410631601d
Added to database: 09/22/2026, 13:03:32 UTC
Last enriched: 09/22/2026, 13:17:39 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 23
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.