CVE-2026-97399: CWE-126 Buffer over-read in The GNU C Library glibc
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.
AI Analysis
Technical Summary
The vulnerability CVE-2026-97399 involves a buffer over-read in the strncasecmp function of glibc versions >=2.24 and <2.45 when optimized for Power8 architecture. The function may read one byte beyond the input buffer size limit, potentially causing a program crash if the next memory page is inaccessible. This occurs when attacker-controlled input strings match exactly up to the edge of a memory page and the following page is not mapped or readable. The CVSS 3.1 base score is 3.7, indicating low severity, with network attack vector, high attack complexity, no privileges required, no user interaction, unchanged scope, and only availability impact (program crash). No known exploits are reported in the wild.
Potential Impact
The impact is limited to a potential denial of service via program crash due to a buffer over-read beyond the input size limit in strncasecmp. There is no confidentiality or integrity impact reported. Exploitation requires specific memory layout conditions and attacker-controlled input strings. No known active exploitation has been observed.
Mitigation Recommendations
No official patch or fix information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, applications using glibc on Power8 architecture should consider avoiding attacker-controlled inputs that could trigger this condition or apply other application-level mitigations to prevent crashes.
CVE-2026-97399: CWE-126 Buffer over-read in The GNU C Library glibc
Description
The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.
CVSS v3.1
Score 3.7low
Affected software
The GNU C Library
glibc
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-97399 involves a buffer over-read in the strncasecmp function of glibc versions >=2.24 and <2.45 when optimized for Power8 architecture. The function may read one byte beyond the input buffer size limit, potentially causing a program crash if the next memory page is inaccessible. This occurs when attacker-controlled input strings match exactly up to the edge of a memory page and the following page is not mapped or readable. The CVSS 3.1 base score is 3.7, indicating low severity, with network attack vector, high attack complexity, no privileges required, no user interaction, unchanged scope, and only availability impact (program crash). No known exploits are reported in the wild.
Potential Impact
The impact is limited to a potential denial of service via program crash due to a buffer over-read beyond the input size limit in strncasecmp. There is no confidentiality or integrity impact reported. Exploitation requires specific memory layout conditions and attacker-controlled input strings. No known active exploitation has been observed.
Mitigation Recommendations
No official patch or fix information is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, applications using glibc on Power8 architecture should consider avoiding attacker-controlled inputs that could trigger this condition or apply other application-level mitigations to prevent crashes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- glibc
- Date Reserved
- 2026-09-24T14:30:14.230Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aba88c5f7a7c54106dc6f33
Added to database: 09/28/2026, 15:33:25 UTC
Last enriched: 09/28/2026, 15:48:02 UTC
Last updated: 09/29/2026, 01:57:22 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.