Executive brief
A vulnerability in the standard C library (glibc) used by many Linux-based systems can cause applications to crash under high load. This occurs when the system's name service cache (nscd) attempts to compare data that is being simultaneously modified by another process. An exploit could lead to a denial-of-service condition, impacting the availability of critical services and applications on the affected system.
Technical details
A race condition exists in the nscd (Name Service Cache Daemon) client-side code within glibc. When NSS-backed functions are called under high load on x86_64 systems, the client may invoke an optimized SSE2 implementation of memcmp on memory regions that are being concurrently modified by other threads or processes. While such concurrent modification is generally undefined behavior, the specific SSE2 optimization introduced in glibc 2.36 (and backported to 2.35) fails to handle the resulting inconsistent state, leading to a segmentation fault (SIGSEGV). This results in a crash of the nscd client and the calling application. The issue has been patched in glibc versions 2.37, 2.36-84, and 2.35-230.
Affected products
- GNU glibc 2.35, 2.36
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 before V3.1.6
Timeline
- 2022-12-07: disclosed: Bug reported to GNU C Library bugzilla
- 2026-03-11: advisory: GLIBC-SA-2026-0004 published
- 2026-03-11: patched: Fixes backported to vulnerable branches
References
- https://sourceware.org/bugzilla/show_bug.cgi?id=29863
- https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0004;hb=HEAD
- https://sourceware.org/git/?p=glibc.git;a=commit;h=8804157ad9da39631703b92315460808eac86b0c
- https://sourceware.org/git/?p=glibc.git;a=commit;h=b712be52645282c706a5faa038242504feb06db5
- http://www.openwall.com/lists/oss-security/2026/03/11/5
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html