Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GNU — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting GNU. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GNU provides a comprehensive collection of free software essential for operating system functionality, primarily serving as the foundational userland for Linux distributions. Its core use case involves delivering command-line utilities, development tools, and system libraries that enable software compilation and execution. Historically, vulnerabilities within the GNU ecosystem have frequently involved buffer overflows and integer overflows, often leading to remote code execution or denial of service conditions. While cross-site scripting is less relevant to its command-line nature, privilege escalation risks have emerged in specific components like coreutils and grep when handling malformed input. Notable security incidents have included critical flaws in GnuPG and Bash, highlighting the importance of rigorous input validation. With seventy-seven recorded CVEs, the project maintains a steady patch cycle, emphasizing stability and security through open-source collaboration and continuous code review processes.

CVE ID Title CVSS Severity Published
CVE-2026-75820 Integer Truncation Leading to Heap Corruption in GNU Aspell — Aspell CWE-190 1.8 Low 2026-10-06
CVE-2026-75819 Out-of-bounds Read in GNU Aspell — Aspell CWE-125 1.8 Low 2026-10-06
CVE-2026-75818 Heap Buffer Overflow in GNU Aspell's prezip utility — Aspell CWE-122 1.8 Low 2026-10-06
CVE-2026-97876 Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address — grub2 CWE-822 6.4 Medium 2026-10-02
CVE-2026-100310 GNU libextractor before 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX — libextractor CWE-426 7.0 High 2026-09-25
CVE-2026-96269 Emacs 28.1-31.1 read-symbol-shorthands远程代码执行漏洞 — Emacs CWE-829 7.5 High 2026-09-22
CVE-2026-91782 GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynrelocs null pointer dereference — Binutils CWE-476 3.3 Low 2026-09-15
CVE-2026-91781 GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference — Binutils CWE-476 3.3 Low 2026-09-15
CVE-2026-91780 GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference — Binutils CWE-476 3.3 Low 2026-09-15
CVE-2026-91779 GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer dereference — Binutils CWE-476 3.3 Low 2026-09-15
CVE-2026-91752 GNU libextractor before 1.15 Stack Overflow via OLE2 — libextractor CWE-789 7.5 High 2026-09-15
CVE-2026-90831 GNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruption — Binutils CWE-119 5.3 Medium 2026-09-14
CVE-2026-90830 GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference — Binutils CWE-476 5.3 Medium 2026-09-14
CVE-2026-90829 GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference — Binutils CWE-476 5.3 Medium 2026-09-14
CVE-2026-90828 GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereference — Binutils CWE-476 5.3 Medium 2026-09-14
CVE-2026-90804 GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflow — Binutils CWE-120 4.8 Medium 2026-09-14
CVE-2026-90803 GNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflow — Binutils CWE-120 5.3 Medium 2026-09-14
CVE-2026-90802 GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference — Binutils CWE-476 4.4 Medium 2026-09-14
CVE-2026-90801 GNU Binutils ld cache.c cache_bwrite buffer overflow — Binutils CWE-120 5.3 Medium 2026-09-14
CVE-2026-90622 GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference — libredwg CWE-476 3.3 Low 2026-09-14
CVE-2026-16599 Denial of Service in GNU wget — wget CWE-606 5.1 Medium 2026-08-25
CVE-2026-77219 GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader — Emacs CWE-190 7.1 High 2026-08-21
CVE-2026-66486 Improper Output Encoding in GNU cpio — cpio CWE-116 4.6 Medium 2026-08-10
CVE-2026-66485 Uncontrolled Memory Allocation in GNU cpio — cpio CWE-789 4.6 Medium 2026-08-10
CVE-2026-66484 Path Traversal in GNU cpio — cpio CWE-22 4.6 Medium 2026-08-10
CVE-2026-71394 Heap Use of Uninitialized Memory in GNU Emacs for Android — Emacs CWE-1284 5.3 Medium 2026-08-10
CVE-2026-71393 Heap Buffer Overflow in GNU Emacs for Android — Emacs CWE-190 5.3 Medium 2026-08-10
CVE-2026-71392 Integer Overflow in GNU Emacs for Android — Emacs CWE-190 5.3 Medium 2026-08-10
CVE-2026-71391 Off-by-One Error in GNU Emacs for Android — Emacs CWE-193 5.3 Medium 2026-08-10
CVE-2026-56390 Arbitrary Output Location Change in GNU Bison — Bison CWE-73 4.6 Medium 2026-07-29

This page lists every published CVE security advisory associated with GNU. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.