Gnu

Glibc

168 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 11.03.2026 13:19:09
  • Zuletzt bearbeitet 14.07.2026 13:18:50

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other pro...

  • EPSS 0.24%
  • Veröffentlicht 18.02.2026 20:25:34
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these fu...

Medienbericht
  • EPSS 0.46%
  • Veröffentlicht 20.01.2026 13:22:46
  • Zuletzt bearbeitet 05.02.2026 17:43:18

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the proces...

Medienbericht
  • EPSS 0.57%
  • Veröffentlicht 15.01.2026 22:16:12
  • Zuletzt bearbeitet 23.01.2026 19:36:50

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configu...

Medienbericht Exploit
  • EPSS 0.36%
  • Veröffentlicht 14.01.2026 21:01:11
  • Zuletzt bearbeitet 03.02.2026 18:26:25

Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that ...

  • EPSS 0.22%
  • Veröffentlicht 05.06.2025 19:20:23
  • Zuletzt bearbeitet 22.10.2025 14:03:33

The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the pow...

  • EPSS 0.26%
  • Veröffentlicht 05.06.2025 18:23:57
  • Zuletzt bearbeitet 01.10.2025 15:37:50

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powe...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 16.05.2025 19:32:50
  • Zuletzt bearbeitet 03.11.2025 20:19:11

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen...

  • EPSS 0.36%
  • Veröffentlicht 22.01.2025 13:15:20
  • Zuletzt bearbeitet 12.05.2026 13:16:27

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to pag...

  • EPSS 1.31%
  • Veröffentlicht 06.05.2024 20:15:11
  • Zuletzt bearbeitet 12.05.2026 12:16:34

nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw...