Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

GNU — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting GNU. AI-powered Chinese analysis, POCs, and references for each vulnerability.

GNU provides a comprehensive collection of free software essential for operating system functionality, primarily serving as the foundational userland for Linux distributions. Its core use case involves delivering command-line utilities, development tools, and system libraries that enable software compilation and execution. Historically, vulnerabilities within the GNU ecosystem have frequently involved buffer overflows and integer overflows, often leading to remote code execution or denial of service conditions. While cross-site scripting is less relevant to its command-line nature, privilege escalation risks have emerged in specific components like coreutils and grep when handling malformed input. Notable security incidents have included critical flaws in GnuPG and Bash, highlighting the importance of rigorous input validation. With seventy-seven recorded CVEs, the project maintains a steady patch cycle, emphasizing stability and security through open-source collaboration and continuous code review processes.

CVE ID Title CVSS Severity Published
CVE-2026-32772 GNU Inetutils 安全漏洞 — inetutils CWE-669 3.4 Low 2026-03-13
CVE-2026-32746 GNU Inetutils 安全漏洞 — inetutils CWE-120 9.8 Critical 2026-03-13
CVE-2026-28372 GNU Inetutils 安全漏洞 — inetutils CWE-829 7.4 High 2026-02-27
CVE-2026-24061 GNU Inetutils 参数注入漏洞 — Inetutils CWE-88 9.8 Critical 2026-01-21
CVE-2025-54770 Grub2: use-after-free in net_set_vlan — grub2 CWE-825 4.9 Medium 2025-11-18
CVE-2025-61664 Grub2: missing unregister call for normal_exit command may lead to use-after-free — grub2 CWE-825 4.9 Medium 2025-11-18
CVE-2025-61663 Grub2: missing unregister call for normal commands may lead to use-after-free — grub2 CWE-825 4.9 Medium 2025-11-18
CVE-2025-61662 Grub2: missing unregister call for gettext command may lead to use-after-free — grub2 7.8 High 2025-11-18
CVE-2025-61661 Grub2: grub2: out-of-bounds write via malicious usb device — grub2 CWE-131 4.8 Medium 2025-11-18
CVE-2025-54771 Grub2: use-after-free in grub_file_close() — grub2 CWE-825 4.9 Medium 2025-11-18
CVE-2025-11840 GNU Binutils ldmisc.c vfinfo out-of-bounds — Binutils CWE-125 3.3 Low 2025-10-16
CVE-2025-11839 GNU Binutils prdbg.c tg_tag_type return value — Binutils CWE-252 3.3 Low 2025-10-16
CVE-2025-11495 GNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow — Binutils CWE-122 3.3 Low 2025-10-08
CVE-2025-11494 GNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds — Binutils CWE-125 3.3 Low 2025-10-08
CVE-2025-11414 GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds — Binutils CWE-125 3.3 Low 2025-10-07
CVE-2025-11413 GNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds — Binutils CWE-125 3.3 Low 2025-10-07
CVE-2025-11412 GNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds — Binutils CWE-125 3.3 Low 2025-10-07
CVE-2025-11083 GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow — Binutils CWE-122 5.3 Medium 2025-09-27
CVE-2025-11082 GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow — Binutils CWE-122 5.3 Medium 2025-09-27
CVE-2025-11081 GNU Binutils objdump.c dump_dwarf_section out-of-bounds — Binutils CWE-125 3.3 Low 2025-09-27
CVE-2025-59378 GNU Guix 安全漏洞 — Guix CWE-669 5.7 Medium 2025-09-15
CVE-2025-8746 GNU libopts __strstr_sse2 memory corruption — libopts CWE-119 3.3 Low 2025-08-09
CVE-2025-8736 GNU cflow Lexer c.c yylex buffer overflow — cflow CWE-120 5.3 Medium 2025-08-08
CVE-2025-8735 GNU cflow Lexer c.c yylex null pointer dereference — cflow CWE-476 3.3 Low 2025-08-08
CVE-2025-8225 GNU Binutils DWARF Section dwarf.c process_debug_info memory leak — Binutils CWE-401 3.3 Low 2025-07-27
CVE-2025-8224 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference — Binutils CWE-476 3.3 Low 2025-07-27
CVE-2025-7546 GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write — Binutils CWE-787 5.3 Medium 2025-07-13
CVE-2025-7545 GNU Binutils objcopy.c copy_section heap-based overflow — Binutils CWE-122 5.3 Medium 2025-07-13
CVE-2025-45582 GNU Tar 安全漏洞 — Tar CWE-24 4.1 Medium 2025-07-11
CVE-2025-6141 GNU ncurses parse_entry.c postprocess_termcap stack-based overflow — ncurses CWE-121 3.3 Low 2025-06-16

This page lists every published CVE security advisory associated with GNU. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.