new file mode 100644
@@ -0,0 +1,113 @@
+From 839898777226a3ed88c0859f25ffe712519b4ead Mon Sep 17 00:00:00 2001
+From: Rocket Ma <marocketbd@gmail.com>
+Date: Fri, 17 Apr 2026 23:48:41 -0700
+Subject: [PATCH] stdio-common: Fix buffer overflow in scanf %mc [BZ #34008]
+
+* stdio-common/vfscanf-internal.c: When enlarging allocated buffer with
+format %mc or %mC, glibc allocates one byte less, leading to
+user-controlled one byte overflow. This commit fixes BZ #34008, or
+CVE-2026-5450.
+
+CVE: CVE-2026-5450
+Upstream-Status: Backport [https://sourceware.org/cgit/glibc/commit/?id=839898777226a3ed88c0859f25ffe712519b4ead]
+Comment: Patch refreshed as per glibc 2.39 source code
+
+Reviewed-by: Carlos O'Donell <carlos@redhat.com>
+Signed-off-by: Rocket Ma <marocketbd@gmail.com>
+Reviewed-by: H.J. Lu <hjl.tools@gmail.com>
+Signed-off-by: Sourav Kumar Pramanik <souravkumar.pramanik@bmwtechworks.in>
+---
+ stdio-common/Makefile | 4 ++++
+ stdio-common/tst-vfscanf-bz34008.c | 48 +++++++++++++++++++++++++++++++++++++
+ stdio-common/vfscanf-internal.c | 6 +++---
+ 3 files changed, 55 insertions(+), 3 deletions(-)
+ create mode 100644 stdio-common/tst-vfscanf-bz34008.c
+
+diff --git a/stdio-common/Makefile b/stdio-common/Makefile
+--- a/stdio-common/Makefile
++++ b/stdio-common/Makefile
+@@ -266,6 +266,7 @@ tests := \
+ tst-vfprintf-width-i18n \
+ tst-vfprintf-width-prec \
+ tst-vfprintf-width-prec-alloc \
++ tst-vfscanf-bz34008 \
+ tst-wc-printf \
+ tstdiomisc \
+ tstgetln \
+@@ -401,6 +402,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \
+ tst-vfprintf-width-prec-ENV = \
+ MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \
+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
++tst-vfscanf-bz34008-ENV = \
++ MALLOC_CHECK_=3 \
++ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
+ tst-printf-bz25691-ENV = \
+ MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \
+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so
+diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c
+new file mode 100644
+--- /dev/null
++++ b/stdio-common/tst-vfscanf-bz34008.c
+@@ -0,0 +1,48 @@
++/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008)
++ Copyright (C) 2026 The GNU Toolchain Authors.
++ This file is part of the GNU C Library.
++
++ The GNU C Library is free software; you can redistribute it and/or
++ modify it under the terms of the GNU Lesser General Public
++ License as published by the Free Software Foundation; either
++ version 2.1 of the License, or (at your option) any later version.
++
++ The GNU C Library is distributed in the hope that it will be useful,
++ but WITHOUT ANY WARRANTY; without even the implied warranty of
++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
++ Lesser General Public License for more details.
++
++ You should have received a copy of the GNU Lesser General Public
++ License along with the GNU C Library; if not, see
++ <https://www.gnu.org/licenses/>. */
++
++#include "malloc/mcheck.h"
++#include <stddef.h>
++#include <stdio.h>
++#include <string.h>
++#include <wchar.h>
++#include <stdlib.h>
++#include <malloc.h>
++#include <support/check.h>
++
++#define WIDTH 0x410
++#define SCANFSTR "%1040mc"
++static int
++do_test (void)
++{
++ mcheck_pedantic (NULL);
++ char *input = malloc (WIDTH + 1);
++ TEST_VERIFY (input != NULL);
++ memset (input, 'A', WIDTH);
++ input[WIDTH] = '\0';
++
++ char *buf = NULL;
++ TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1);
++ TEST_VERIFY (buf != NULL);
++
++ free (buf);
++ free (input);
++ return 0;
++}
++
++#include <support/test-driver.c>
+diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c
+--- a/stdio-common/vfscanf-internal.c
++++ b/stdio-common/vfscanf-internal.c
+@@ -857 +857 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
+- + (strsize >= width ? width - 1 : strsize);
++ + (strsize >= width ? width : strsize);
+@@ -928 +928 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
+- = strsize + (strsize > width ? width - 1 : strsize);
++ = strsize + (strsize >= width ? width : strsize);
+@@ -983 +983 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr,
+- = strsize + (strsize > width ? width - 1 : strsize);
++ = strsize + (strsize >= width ? width : strsize);
+--
+2.43.7
@@ -57,6 +57,7 @@ SRC_URI = "${GLIBC_GIT_URI};branch=${SRCBRANCH};name=glibc \
file://0023-qemu-stale-process.patch \
file://0001-stdlib-Add-single-threaded-fast-path-to-rand.patch \
file://0024-CVE-2026-5435.patch \
+ file://CVE-2026-5450.patch \
"
S = "${WORKDIR}/git"
B = "${WORKDIR}/build-${TARGET_SYS}"