- What: glibc security update released
- Impact: Red Hat Enterprise Linux 9 systems may be affected
Red Hat Product Errata RHSA-2026:42952 - Security Advisory Issued: 2026-07-21 Updated: 2026-07-21 RHSA-2026:42952 - Security Advisory Overview Updated Packages Synopsis Moderate: glibc security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for glibc is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. Security Fix(es): glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings (CVE-2026-5928) glibc: glibc: Out-of-bounds write via TSIG record processing (CVE-2026-5435) glibc: glibc: Application crash or uninitialized memory read via crafted DNS response (CVE-2026-6238) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2459854 - CVE-2026-5928 glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings BZ - 2463465 - CVE-2026-5435 glibc: glibc: Out-of-bounds write via TSIG record processing BZ - 2463539 - CVE-2026-6238 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response CVEs CVE-2026-5435 CVE-2026-5928 CVE-2026-6238 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM glibc-2.34-274.el9_8.src.rpm SHA-256: 14d3035eb38ed4c0523fbc1273dc78e6a8ed1ee9db4545bec182fccf0dd53231 x86_64 glibc-2.34-274.el9_8.i686.rpm SHA-256: 04626b7465c808dcf0de0d308c74e88b3ba89cd2efa099fdd32687456b371aa8 glibc-2.34-274.el9_8.x86_64.rpm SHA-256: 3a68581527ea2aa67a57610951bd9722019cc32db691cace00dc7478cab312ec glibc-all-langpacks-2.34-274.el9_8.x86_64.rpm SHA-256: 3972b10aec54d0d4dc27d0f8f413616370c06659806e85f60b33c64af6c5d212 glibc-benchtests-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: f152a819eed6dae97ee849dbdf91def80e0c9578de04620ab0542c4924985df2 glibc-benchtests-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: f152a819eed6dae97ee849dbdf91def80e0c9578de04620ab0542c4924985df2 glibc-benchtests-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: 1b397e6a1aba0beb6f31339644ceb102ec3b41f08452d781f755b7825e3893b7 glibc-benchtests-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: 1b397e6a1aba0beb6f31339644ceb102ec3b41f08452d781f755b7825e3893b7 glibc-common-2.34-274.el9_8.x86_64.rpm SHA-256: d741ab036ed8b97022052adb291a749a0ca1d5e492bd906aa7da95af9866bd2b glibc-common-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: f36946af20dc4912517667a30d18f5c0de6ba3b0f184ca606c5633acc43de16d glibc-common-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: f36946af20dc4912517667a30d18f5c0de6ba3b0f184ca606c5633acc43de16d glibc-common-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: 80f0e4ecb4759e3a79cb753a005051d96d4046930774c22da9c601f472cd5b47 glibc-common-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: 80f0e4ecb4759e3a79cb753a005051d96d4046930774c22da9c601f472cd5b47 glibc-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: 3448e5397f286776f445c06fb2aba2ec674912aac2df2ddc457e293ce9f295a8 glibc-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: 3448e5397f286776f445c06fb2aba2ec674912aac2df2ddc457e293ce9f295a8 glibc-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: 3a770276bcacb4b49f78107a5e2004440d869cf2ad183c5f03c6444970f9de9b glibc-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: 3a770276bcacb4b49f78107a5e2004440d869cf2ad183c5f03c6444970f9de9b glibc-debugsource-2.34-274.el9_8.i686.rpm SHA-256: 33e94e511338264630bf8e49f51f1e40e327ca6d4b0d3329c214d0dbc5c09758 glibc-debugsource-2.34-274.el9_8.i686.rpm SHA-256: 33e94e511338264630bf8e49f51f1e40e327ca6d4b0d3329c214d0dbc5c09758 glibc-debugsource-2.34-274.el9_8.x86_64.rpm SHA-256: 7ab8db561b97472d58730fc6d32fa61d1cb6e91712bb68356351b3f812d027a3 glibc-debugsource-2.34-274.el9_8.x86_64.rpm SHA-256: 7ab8db561b97472d58730fc6d32fa61d1cb6e91712bb68356351b3f812d027a3 glibc-devel-2.34-274.el9_8.i686.rpm SHA-256: 079561b0de1e9bc05955d3b2ffebc0239877b22f596a7d1cf6ccb68b591e371b glibc-devel-2.34-274.el9_8.x86_64.rpm SHA-256: e6176ffaf004619a3c4c6d69fc3499a90697cfea221c46e014d605e452bb859d glibc-doc-2.34-274.el9_8.noarch.rpm SHA-256: 02c4d5c896e0a28f243145510bf988f22f738d3b747b4da9aa4c3e66580f7c69 glibc-gconv-extra-2.34-274.el9_8.i686.rpm SHA-256: 2e123f77dc702ba666cf36e250caf28a5076e2a81f3244229f8714b073364a29 glibc-gconv-extra-2.34-274.el9_8.x86_64.rpm SHA-256: fc95653733ca0cf6b9fafc2485573f123b62831dc17f2fc1e8d7cd033a2f77d4 glibc-gconv-extra-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: 031a269016d21b2b7e34630dc775d4685f9fbd8b376605900df226a7a55d52b1 glibc-gconv-extra-debuginfo-2.34-274.el9_8.i686.rpm SHA-256: 031a269016d21b2b7e34630dc775d4685f9fbd8b376605900df226a7a55d52b1 glibc-gconv-extra-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: aaae27a2b9f23ff4dd800a5641914853c6760c2180388abed1d47cc7d9546eed glibc-gconv-extra-debuginfo-2.34-274.el9_8.x86_64.rpm SHA-256: aaae27a2b9f23ff4dd800a5641914853c6760c2180388abed1d47cc7d9546eed glibc-headers-2.34-274.el9_8.x86_64.rpm SHA-256: 98c8a2b2939f7decf299713dd4625c1ca1e8a3b536d6607db3cde04e32799bcd glibc-langpack-aa-2.34-274.el9_8.x86_64.rpm SHA-256: 7efd5d2748cf0c7cd7b1cc324babe118ea8b7509c433ad29dc5c1981ced78833 glibc-langpack-af-2.34-274.el9_8.x86_64.rpm SHA-256: ae39d3d6a4af4511fac4ab13d8a00c447d41272c2146114cbc5720a3f1e8f97c glibc-langpack-agr-2.34-274.el9_8.x86_64.rpm SHA-256: 85874d466e976f466d4649664f310ca04391315c207c65a4b65b7ed3bace4fc5 glibc-langpack-ak-2.34-274.el9_8.x86_64.rpm SHA-256: 52f2aad3804c1bdb68e6a4678b53daa277cd2122c6177cb7bfa35dee4e325158 glibc-langpack-am-2.34-274.el9_8.x86_64.rpm SHA-256: 5131a8331172a17cfc3f98111e54fdd7695be3ffe5e6c1e0f2a5a5332a6766ab glibc-langpack-an-2.34-274.el9_8.x86_64.rpm SHA-256: 71be1f41bd7147e85764cfdd2633953f611345a52b0a7bc6b2b7a765b66717d2 glibc-langpack-anp-2.34-274.el9_8.x86_64.rpm SHA-256: 3218224a92f4501550aa668c1f937ac091894bdb8352612a41316a55f779e2a3 glibc-langpack-ar-2.34-274.el9_8.x86_64.rpm SHA-256: eed47209a4a6c0da4bd69128635bfcfb82f77624905d67de9f0564a6ccca9eee glibc-langpack-as-2.34-274.el9_8.x86_64.rpm SHA-256: 42e4cc201cdad160384cb70f047889a69601e4aa6ce4c44760beaaf003ee1b4a glibc-langpack-ast-2.34-274.el9_8.x86_64.rpm SHA-256: 9dc54c91a47b738d83699dc428207117b89651880c5e093c5fde3568409e207c glibc-langpack-ayc-2.34-274.el9_8.x86_64.rpm SHA-256: 9b1207bbb6e3e97f85d5782fd5760fbed140e6b008c739d3aac11f32e0a60af4 glibc-langpack-az-2.34-274.el9_8.x86_64.rpm SHA-256: 7014f7d7abcbfaa3c952f9bb3019626c11c187a4faf2dc01c47a581c6f79f5cb glibc-langpack-be-2.34-274.el9_8.x86_64.rpm SHA-256: 083d4da777826fbc096d9f01236a8be6fe99db892eb171600fbc7746d490c37a glibc-langpack-bem-2.34-274.el9_8.x86_64.rpm SHA-256: d04e04e56ba4d9d8bb90a597fc32481d263ff537f93b140ce57565125bd787c4 glibc-langpack-ber-2.34-274.el9_8.x86_64.rpm SHA-256: 4ca027317307af0046afff94784f533208583cc5ee4fd90c285d3a3e6546d109 glibc-langpack-bg-2.34-274.el9_8.x86_64.rpm SHA-256: e85fb073bc8d3cb8c128832ee33726a4af2bf23cff17eb3b640b224f7b7cff1e glibc-langpack-bhb-2.34-274.el9_8.x86_64.rpm SHA-256: 43fa9ee9cd433987bd9dd2564f97873d44a6b3b30ae26d4be42296f348f0a770 glibc-langpack-bho-2.34-274.el9_8.x86_64.rpm SHA-256: 1f49355d7b540957adceec652f337cc5ee36c87fb5a27bbc242e14053b781f27 glibc-langpack-bi-2.34-274.el9_8.x86_64.rpm SHA-256: 0789611c57293e74b9d654ccd867134fc6b6655d2129698b43fb579ea13a9c61 glibc-langpack-bn-2.34-274.el9_8.x86_64.rpm SHA-256: 3be8f45fbf05154