---
id: CVE-2026-97399
title: >-
  The strncasecmp function in the GNU C Library 2.24 and later optimized for the
  Power8 architecture may read one byte beyond the input size limit, which may
  crash a program when that byte is not readable.


  This condition may happen when t…
summary: >-
  The strncasecmp function in the GNU C Library 2.24 and later optimized for the
  Power8 architecture may read one byte beyond the input size limit, which may
  crash a program when that byte is not readable.


  This condition may happen when t…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-126
vendor: The GNU C Library
product: glibc
affected:
  - glibc >= 2.24 < 2.45
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T16:17:18.550'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97399'
references:
  - url: 'https://sourceware.org/bugzilla/show_bug.cgi?id=34683'
    label: 3ff69d7a-14f2-4f67-a097-88dee7810d18
  - url: >-
      https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0024
    label: 3ff69d7a-14f2-4f67-a097-88dee7810d18
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-28T15:33:28.320527Z'
ingestedAt: '2026-09-28T16:15:01.375Z'
---

## Overview

The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.

This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
