https://www.phoronix.com/news/Glibc-Security-Fix-For-1996-Bug Phoronix * Articles & Reviews * News Archive * Forums * Premium Ad-Free * Contact * Popular Categories * Close * * Articles & Reviews * News Archive * Forums * Premium * Contact * Categories Computers Display Drivers Graphics Cards Linux Gaming Memory Motherboards Processors Software Storage Operating Systems Peripherals * [ ] [Search] CVE-2026-0915: GNU C Library Fixes A Security Issue Present Since 1996 Written by Michael Larabel in Linux Security on 17 January 2026 at 06:25 AM EST. 15 Comments LINUX SECURITY CVE-2026-0915 was published on Friday as a security issue with the GNU C Library "glibc" for code introduced 30 years ago. The latest Glibc Git code is now patched for this issue introduced in 1996. The oss-security bulletin sums up the issue as the getnetbyaddr and getnetbyaddr_r functions leaking the stack contents to the DNS resovler. It does note though that it is rare to call these APIs with a network value of zero and for an attacker to take advantage of this issue it can only leak the adjacent stack. The loss of confidentiality is ultimately limited but could be used to help in an address space layout randomization (ASLR) bypass. Thankfully at least the scope is rather limited and should ultimately have minimal impact but rather surprising it took 30 years for a zero value case to be tested and in turn properly handled by this very important library. The NSS DNS back-end is now fixed in Glibc as it turns out a network value of zero was never tested and can result in the DNS query being constructed from uninitialized stack bytes. With the newest Glibc code, a default query is now constructed for cases where the default network value is zero. The issue is fixed by this Git commit now in glibc.git. The problematic code introduced this problem happened all the way back in June 1996. glibc bug since 1996 CVE-2026-0861 was also disclosed this week for Glibc where passing too large of an alignment to glibc's memalign functions could result in an integer overflow and in turn heap corruption. At least that problematic code was only introduced back in 2019 and is also now fixed in Glibc Git. Glibc 2.43 is expected to be released by early February as the next scheduled update to the GNU C Library. 15 Comments Tweet Related News Torvalds On Linux Security Modules: "I Already Think We Have Too Many Of Those Pointless Things" Linux 6.19 Will Allow Enforcing IPE Security Checks On Indirectly Executed Scripts Scoped User Access In Linux 6.19 To Reduce Speculation Barriers & Its Performance Hit Linux To Gain ML-DSA/Dilithium Post-Quantum Cryptography For Module Signing AMD Dev Proposes Dynamic Mitigations For Linux: Run-Time Toggling Of CPU Mitigations Linux Now Disabling TPM Bus Encryption By Default For Performance Reasons About The Author Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com. Popular News This Week Linus Torvalds' Latest Open-Source Project Is AudioNoise - Made With The Help Of Vibe Coding Latest SteamOS Beta Now Includes NTSYNC Kernel Driver Budgie 10.10 Released: Officially Migrated From X11 To Wayland Fedora Games Lab Approved To Switch To KDE Plasma, Become A Better Linux Gaming Showcase KDE Plasma 6.6 Beta Released With Plasma Login Manager, Plasma Setup Wine 11.0 Planned For Release Tomorrow With NTSync Support, Better WoW64 JPEG-XL Image Support Returns To Latest Chrome / Chromium Code Debian 13.3 Released With Many Security & Bug Fixes Latest Linux News Important AMDGPU & AMDKFD Driver Improvements Readied For Linux 6.20~7.0 FreeBSD 15.1 Aims To Have KDE Desktop Installer Option CVE-2026-0915: GNU C Library Fixes A Security Issue Present Since 1996 KDE Begins Landing Features For Plasma 6.7, Some Last Minute Plasma 6.6 Improvements Shotcut 26.1 Beta Video Editor Adds New Hardware Decoder Options Upcoming exFAT Linux Driver Patch Can Boost Sequential Read Performance By ~10% Adobe Photoshop 2025 Installer Now Working On Linux With Patched Wine Linux ThinkPad Driver Ready For Reporting Damage Device - Starting With Bad USB-C Ports Linux 7.0 Looks To Enable Intel TSX By Default On Capable CPUs For Better Performance Ubuntu 26.04 Aims To Deliver Better NVIDIA Wayland Performance Atop GNOME Show Your Support, Go Premium Phoronix Premium allows ad-free access to the site, multi-page articles on a single page, and other features while supporting this site's continued operations. Latest Featured Articles AMD EPYC 8004 "Siena" Shows Some Nice Linux Performance Gains Over The Past Two Years Lenovo ThinkPad P1 Gen 8: A High-End, Intel + NVIDIA Mobile Workstation Great For Linux Use An Early Run With Ubuntu 26.04 On AMD EPYC Turin - The Current Performance Gains Over Ubuntu 24.04 LTS Intel's Fantastic New Open-Source Demonstrator For AMX-BF16: Over 4x The Performance At 69% The Power The Surprising Spectre BHI Mitigation Performance Impact On Meteor Lake Support Phoronix The mission at Phoronix since 2004 has centered around enriching the Linux hardware experience. In addition to supporting our site through advertisements, you can help by subscribing to Phoronix Premium. You can also contribute to Phoronix through tips/donations via PayPal or Stripe. Phoronix Media --------------------------------------------------------------------- * Contact * Michael Larabel Phoronix Premium --------------------------------------------------------------------- * Support Phoronix * While Having Ad-Free Browsing, * Single-Page Article Viewing Share --------------------------------------------------------------------- * Facebook * Twitter / X * Legal Disclaimer, Privacy Policy, Cookies | Privacy Manager | Contact * Copyright (c) 2004 - 2026 by Phoronix Media. * All trademarks used are properties of their respective owners. All rights reserved.