Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GNU — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting GNU. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GNU provides a comprehensive collection of free software essential for operating system functionality, primarily serving as the foundational userland for Linux distributions. Its core use case involves delivering command-line utilities, development tools, and system libraries that enable software compilation and execution. Historically, vulnerabilities within the GNU ecosystem have frequently involved buffer overflows and integer overflows, often leading to remote code execution or denial of service conditions. While cross-site scripting is less relevant to its command-line nature, privilege escalation risks have emerged in specific components like coreutils and grep when handling malformed input. Notable security incidents have included critical flaws in GnuPG and Bash, highlighting the importance of rigorous input validation. With seventy-seven recorded CVEs, the project maintains a steady patch cycle, emphasizing stability and security through open-source collaboration and continuous code review processes.

CVE ID Title CVSS Severity Published
CVE-2026-56389 Arbitrary Command Execution in GNU Bison — Bison CWE-78 6.8 Medium 2026-07-29
CVE-2026-56392 Heap-based Buffer Overflow in GNU coreutils — coreutils CWE-122 1.8 Low 2026-07-24
CVE-2026-56391 Out‑of‑bounds Read in GNU coreutils — coreutils CWE-125 4.6 Medium 2026-07-24
CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils — diffutils CWE-190 2.1 Low 2026-07-22
CVE-2026-40553 Stack-based buffer overflow in gawk — gawk CWE-121 - - 2026-07-13
CVE-2026-40469 Heap buffer overflow in gawk — gawk CWE-190 - - 2026-07-13
CVE-2026-40468 Heap buffer overflow in gawk — gawk CWE-190 - - 2026-07-13
CVE-2026-40467 Use after free in gawk — gawk CWE-416 - - 2026-07-13
CVE-2026-15520 GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow — LibreDWG CWE-122 5.3 Medium 2026-07-13
CVE-2026-15184 GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference — LibreDWG CWE-476 3.3 Low 2026-07-09
CVE-2026-15182 GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow — LibreDWG CWE-122 5.3 Medium 2026-07-09
CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch — patch CWE-835 - - 2026-07-09
CVE-2026-56288 NULL Pointer Dereference in GNU patch — patch CWE-476 - - 2026-07-09
CVE-2026-41992 Global Buffer Overflow in GNU gzip — gzip CWE-126 6.9 Medium 2026-06-29
CVE-2026-41991 Predictable Temporary File in GNU gzip — gzip CWE-377 - - 2026-06-29
CVE-2026-57053 GNU libidn 输入验证错误漏洞 — libidn CWE-1284 4.0 Medium 2026-06-23
CVE-2026-56968 GNU SASL 输入验证错误漏洞 — GNU SASL CWE-839 3.7 Low 2026-06-23
CVE-2026-56355 GNU Savane 处理逻辑错误漏洞 — Savane CWE-696 3.7 Low 2026-06-20
CVE-2026-9605 GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow — libredwg CWE-122 7.3 High 2026-05-26
CVE-2026-9530 GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds — LibreDWG CWE-125 3.3 Low 2026-05-26
CVE-2026-9529 GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference — LibreDWG CWE-476 3.3 Low 2026-05-26
CVE-2026-9504 GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds — LibreDWG CWE-125 3.3 Low 2026-05-25
CVE-2026-9503 GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference — LibreDWG CWE-476 3.3 Low 2026-05-25
CVE-2026-9502 GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow — LibreDWG CWE-122 5.3 Medium 2026-05-25
CVE-2026-9501 GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion — LibreDWG CWE-617 3.3 Low 2026-05-25
CVE-2026-9500 GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow — LibreDWG CWE-122 5.3 Medium 2026-05-25
CVE-2026-48829 GNU SASL 代码问题漏洞 — GNU SASL CWE-476 7.5 High 2026-05-24
CVE-2026-1858 wget2 Improper Certificate Validation — wget2 CWE-20 4.8 Medium 2026-04-29
CVE-2026-5958 Race Condition in GNU Sed — Sed CWE-367 5.9AI Medium AI 2026-04-20
CVE-2025-69720 ncurses 安全漏洞 — ncurses CWE-121 7.3 High 2026-03-19

This page lists every published CVE security advisory associated with GNU. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.