Views
5

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8737-1 updates GNU C Library (glibc) to address multiple vulnerabilities, including buffer overflow, stack overflow, out-of-bounds access, and hang issues. Ubuntu 26.04 LTS is affected by CVE-2026-19499, and the fix is available in libc6 2.43-2ubuntu2.4.

Update Details

Security

  • Fixed a buffer overflow in strfmon that could allow denial of service or arbitrary code execution; affects Ubuntu 26.04 LTS only (CVE-2026-19499).
  • Fixed an out-of-bounds stack array access in tdelete that could allow denial of service or arbitrary code execution (CVE-2026-19542).
  • Fixed incorrect memory handling in wordexp with the WRDE_APPEND flag that could cause denial of service (CVE-2026-6368).
  • Fixed a stack overflow in wordexp when expanding ~ paths with a long username, which could cause denial of service or arbitrary code execution (CVE-2026-6791).
  • Fixed hangs in the SHIFT_JISX0213 and EUC_JISX0213 character set converters that could cause denial of service (CVE-2026-77117, CVE-2026-80489).

Hints

  • A standard system update will apply the necessary changes.
  • For Ubuntu 26.04 LTS (resolute), update libc6 to 2.43-2ubuntu2.4.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 26.04 LTS (Resolute Raccoon)

Version: libc6 2.43-2ubuntu2.4

Vendor release date: Sep 8, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 9, 2026

Description: Server operating system for Linux infrastructure and workloads.