PT-2026-69895 · Canonical · Ubuntu

CVE-2026-6791

·

Published

2026-07-06

·

Updated

2026-09-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An issue exists in the wordexp function when expanding paths that start with a tilde (~) followed by a username. The internal parse tilde() function allocates memory for the username on the stack using the strndupa macro without performing bounds checks on the length of the user-supplied input. Providing an excessively long username can exhaust the thread's stack space, allowing an attacker to trigger a stack clash, which occurs when the stack grows into another memory region.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95492
CVE-2026-6791
ECHO-9658-3093-2999
OESA-2026-3418
OPENSUSE-SU-2026:11660-1
RHSA-2026:53069
USN-8737-1
USN-8737-2

Affected Products

Ubuntu