Junglewise Threat Intelligence

CVE-2026-95619: libstdc++ integer overflow in aligned operator new

CVE-2026-95619 · Severity: high · CVSS 7.7 · Published 2026-09-22

Vendors: Gnu.

Executive brief

libstdc++ is a core C++ standard library used by applications to manage memory and perform computations. An integer overflow in its memory allocation function can cause the library to allocate too little memory for large requests, leading to memory corruption or crashes when the application writes to the undersized buffer.

Technical details

An integer overflow vulnerability exists in the aligned operator new function of libstdc++ when processing large allocation requests. The overflow causes undersized memory allocation, leading to out-of-bounds writes and potential memory corruption or application instability. Exploitation requires an attacker to control or influence allocation size parameters, typically requiring code execution or unsafe input handling in the calling application.

Affected products

  • GNU libstdc++

References