Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GNU — Vulnerabilities & Security Advisories 112

Browse all 112 CVE security advisories affecting GNU. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GNU provides a comprehensive collection of free software essential for operating system functionality, primarily serving as the foundational userland for Linux distributions. Its core use case involves delivering command-line utilities, development tools, and system libraries that enable software compilation and execution. Historically, vulnerabilities within the GNU ecosystem have frequently involved buffer overflows and integer overflows, often leading to remote code execution or denial of service conditions. While cross-site scripting is less relevant to its command-line nature, privilege escalation risks have emerged in specific components like coreutils and grep when handling malformed input. Notable security incidents have included critical flaws in GnuPG and Bash, highlighting the importance of rigorous input validation. With seventy-seven recorded CVEs, the project maintains a steady patch cycle, emphasizing stability and security through open-source collaboration and continuous code review processes.

CVE IDTitleCVSSSeverityPublished
CVE-2026-66486 Improper Output Encoding in GNU cpio — cpioCWE-116 4.6 Medium2026-08-10
CVE-2026-66485 Uncontrolled Memory Allocation in GNU cpio — cpioCWE-789 4.6 Medium2026-08-10
CVE-2026-66484 Path Traversal in GNU cpio — cpioCWE-22 4.6 Medium2026-08-10
CVE-2026-71394 Heap Use of Uninitialized Memory in GNU Emacs for Android — EmacsCWE-1284 5.3 Medium2026-08-10
CVE-2026-71393 Heap Buffer Overflow in GNU Emacs for Android — EmacsCWE-190 5.3 Medium2026-08-10
CVE-2026-71392 Integer Overflow in GNU Emacs for Android — EmacsCWE-190 5.3 Medium2026-08-10
CVE-2026-71391 Off-by-One Error in GNU Emacs for Android — EmacsCWE-193 5.3 Medium2026-08-10
CVE-2026-56390 Arbitrary Output Location Change in GNU Bison — BisonCWE-73 4.6 Medium2026-07-29
CVE-2026-56389 Arbitrary Command Execution in GNU Bison — BisonCWE-78 6.8 Medium2026-07-29
CVE-2026-56392 Heap-based Buffer Overflow in GNU coreutils — coreutilsCWE-122 1.8 Low2026-07-24
CVE-2026-56391 Out‑of‑bounds Read in GNU coreutils — coreutilsCWE-125 4.6 Medium2026-07-24
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils — diffutilsCWE-190 2.1 Low2026-07-22
CVE-2026-40553 Stack-based buffer overflow in gawk — gawkCWE-121--2026-07-13
CVE-2026-40469 Heap buffer overflow in gawk — gawkCWE-190--2026-07-13
CVE-2026-40468 Heap buffer overflow in gawk — gawkCWE-190--2026-07-13
CVE-2026-40467 Use after free in gawk — gawkCWE-416--2026-07-13
CVE-2026-15520 GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow — LibreDWGCWE-122 5.3 Medium2026-07-13
CVE-2026-15184 GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference — LibreDWGCWE-476 3.3 Low2026-07-09
CVE-2026-15182 GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow — LibreDWGCWE-122 5.3 Medium2026-07-09
CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch — patchCWE-835--2026-07-09
CVE-2026-56288 NULL Pointer Dereference in GNU patch — patchCWE-476--2026-07-09
CVE-2026-41992 Global Buffer Overflow in GNU gzip — gzipCWE-126--2026-06-29
CVE-2026-41991 Predictable Temporary File in GNU gzip — gzipCWE-377--2026-06-29
CVE-2026-57053 GNU libidn 输入验证错误漏洞 — libidnCWE-1284 4.0 Medium2026-06-23
CVE-2026-56968 GNU SASL 输入验证错误漏洞 — GNU SASLCWE-839 3.7 Low2026-06-23
CVE-2026-56355 GNU Savane 处理逻辑错误漏洞 — SavaneCWE-696 3.7 Low2026-06-20
CVE-2026-9605 GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow — libredwgCWE-122 7.3 High2026-05-26
CVE-2026-9530 GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds — LibreDWGCWE-125 3.3 Low2026-05-26
CVE-2026-9529 GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference — LibreDWGCWE-476 3.3 Low2026-05-26
CVE-2026-9504 GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds — LibreDWGCWE-125 3.3 Low2026-05-25

This page lists every published CVE security advisory associated with GNU. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.