Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. | |
| Title | wordexp with WRDE_APPEND can return or use invalid memory | |
| Weaknesses | CWE-908 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: glibc
Published:
Updated: 2026-08-10T18:40:11.601Z
Reserved: 2026-04-15T15:07:08.926Z
Link: CVE-2026-6368
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-10T20:45:05Z