Echo: glibc: security update to 2.41-12+deb13u3+e4

medium Tenable Self-Hosted Container Security Plugin ID 464108

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer
past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete
implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while
descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and
write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly
40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must
drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The
written value is a pointer into a tree node and is not directly attacker controlled. No affected
application in common distributions has been identified. (CVE-2026-19542)

Solution

Update the glibc library and its related packages to version 2.41-12+deb13u3+e4 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-19542

Plugin Details

Severity: Medium

ID: 464108

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.19

CVSS v2

Risk Factor: Medium

Base Score: 5.1

Temporal Score: 3.8

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-19542

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/23/2026

Vulnerability Publication Date: 8/27/2026

Reference Information

CVE: CVE-2026-19542

IAVA: 2026-A-0897