DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-vcmc-j592-5cr9

Package

libc-bin-2.44

Component

libc-bin-2.44

Latest update

Fixed

Fixed version

2.44-r4

Aliases

Severity

7.7

High

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-19499

Updates

Status

Fixed

Fixed version

2.44-r4

Impact

Fixed by upstream stable-branch backport 63b53df549451a5d69fcba6d7612ea99f517e8e3 on release/2.44/master, a cherry-pick of 2.45 commit b090cf226ff65b913e41536f1f573f500855615c. Present from epoch 2.44-r4 (pin 5c479454d123); absent at r3 and earlier (pin ae9225d55963). Verified by reading stdlib/strfmon_l.c at the pinned build commit, and functionally: the upstream reproducer for bug 34510 segfaults against glibc-2.44-r1 and returns -1/E2BIG against 2.44-r6. Note that GLIBC-SA-2026-0017 omits this cherry-pick from its Fix-Commit list.

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.