Skip to main content
Version: v1.4.x

CVE-2026-97399

CVE Details​

Visit the official vulnerability details page for CVE-2026-97399 to learn more.

Initial Publication​

09/28/2026

Last Update​

09/29/2026

Third Party Dependency​

glibc

NIST CVE Summary​

The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.

This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.

CVE Severity​

3.7

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

Awaiting Analysis

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.4.0⚠️ Impacted⚠️ Impacted
1.3.2⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.