Skip to content
Rota Nacional

Cyber ·

GNU C Library warns of out-of-bounds read on Power8

A notice published on September 28, 2026 describes a possible one-byte out-of-bounds read in Power8-optimized strncasecmp in GNU C Library 2.24 and later.

The GNU C Library published security notices on September 28, 2026. The available excerpt highlights GLIBC-SA-2026-0024: the Power8-optimized strncasecmp function in versions 2.24 and later may read one byte beyond the specified input size. If that byte cannot be read, the program may fail. The notice says this can occur when strings passed to the function are controlled by an attacker; the supplied excerpt ends before completing that description.

The feed content is an automatic translation and the supplied excerpt does not include all notice details. To assess impact and recommended actions, consult the original notice dated September 28 in the oss-sec archive and verify the full text and identifier GLIBC-SA-2026-0024. If using AI to study or apply the material, remove personal data and secrets from prompts, and validate technical conclusions against the relevant notice and source code.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free