Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

The GNU C Library — Vulnerabilities & Security Advisories 32

Browse all 32 CVE security advisories affecting The GNU C Library. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The GNU C Library serves as the fundamental implementation of the standard C library for the Linux operating system, providing essential system calls and functions required by nearly all user-space applications. Historically, its widespread adoption has made it a frequent target for critical vulnerabilities, particularly those involving buffer overflows, integer overflows, and memory corruption issues that can lead to remote code execution or privilege escalation. While it does not typically suffer from web-specific flaws like cross-site scripting, its core role in handling input parsing and memory management has resulted in significant incidents, such as the GHOST vulnerability, which allowed attackers to execute arbitrary code through a simple function call. With numerous CVEs on record, the library remains a critical component where security patches are vital for maintaining system integrity across diverse Linux distributions.

Top products by The GNU C Library: glibc
CVE ID Title CVSS Severity Published
CVE-2026-97399 One-byte overread in strncasecmp on Power8 — glibc CWE-126 3.7 Low 2026-09-28
CVE-2026-95818 AT_SECURE program buffer overflow via $ORIGIN processing — glibc CWE-121 3.6 Low 2026-09-22
CVE-2026-86805 AT_SECURE programs may load attacker-controlled code via $ORIGIN — glibc CWE-367 6.3 Medium 2026-09-22
CVE-2026-8674 Assertion failure in the DNS stub resolver with a long search domain — glibc CWE-617 5.3 Medium 2026-09-17
CVE-2026-80489 EUC_JISX0213 decoding may hang on crafted input — glibc CWE-835 5.9 Medium 2026-09-15
CVE-2026-77117 SHIFT_JISX0213 decoding may hang on crafted input — glibc CWE-835 5.9 Medium 2026-09-15
CVE-2026-19542 Stack-based out-of-bounds write in tdelete during tree rebalancing — glibc CWE-121 5.6 Medium 2026-09-14
CVE-2026-19499 Buffer overflow in strfmon and strfmon_l right-justification padding — glibc CWE-122 7.7 High 2026-09-14
CVE-2026-89092 Stack overflow in nscd due to unbounded alloca use — glibc CWE-789 4.2 Medium 2026-09-11
CVE-2026-18374 GNU C Library 缓冲区错误漏洞 — glibc 4.9 Medium 2026-08-27
CVE-2026-6791 Potential stack-based buffer clash during tilde expansion in wordexp — glibc CWE-121 6.6 Medium 2026-08-10
CVE-2026-6238 Buffer overread in ns_printrrf with corrupted RDATA field — glibc CWE-126 8.2AI High AI 2026-04-28
CVE-2026-5435 Potential buffer overflow in ns_sprintrrf TSIG handling path — glibc CWE-787 9.8AI Critical AI 2026-04-28
CVE-2026-5450 scanf %mc off-by-one heap buffer overflow — glibc CWE-122 9.8AI Critical AI 2026-04-20
CVE-2026-5928 Potential buffer under-read in ungetwc — glibc CWE-127 9.1AI Critical AI 2026-04-20
CVE-2026-4046 iconv crash due to assertion failure with untrusted input — glibc CWE-617 7.5 - 2026-03-30
CVE-2026-4438 gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames — glibc CWE-20 4.3 - 2026-03-20
CVE-2026-4437 gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response — glibc CWE-125 7.5 - 2026-03-20
CVE-2026-3904 GNU C Library 安全漏洞 — glibc CWE-366 6.8AI Medium AI 2026-03-11
CVE-2025-15281 wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory — glibc CWE-908 7.5AI High AI 2026-01-20
CVE-2026-0915 getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler — glibc CWE-908 7.5AI High AI 2026-01-15
CVE-2026-0861 Integer overflow in memalign leads to heap corruption — glibc CWE-190 9.8AI Critical AI 2026-01-14
CVE-2025-8058 GNU C Library 安全漏洞 — glibc CWE-415 9.8 - 2025-07-23
CVE-2025-5745 GNU C Library 安全漏洞 — glibc 9.4 - 2025-06-05
CVE-2025-5702 GNU C Library 安全漏洞 — glibc 9.4 - 2025-06-05
CVE-2025-4802 GNU C Library 安全漏洞 — glibc CWE-426 7.5AI High AI 2025-05-16
CVE-2025-0395 GNU C Library 安全漏洞 — glibc CWE-131 9.8 - 2025-01-22
CVE-2024-33602 nscd: netgroup cache assumes NSS callback uses in-buffer strings — glibc CWE-466 8.4 - 2024-05-06
CVE-2024-33601 nscd: netgroup cache may terminate daemon on memory allocation failure — glibc CWE-617 6.2 - 2024-05-06
CVE-2024-33600 nscd: Null pointer crashes after notfound response — glibc CWE-476 7.5 - 2024-05-06

This page lists every published CVE security advisory associated with The GNU C Library. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.