Search CVE reports


Toggle filters

11 – 20 of 176 results


CVE-2026-5450

Medium priority

Some fixes available 3 of 8

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-5358

Medium priority
Not affected

Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release Not in release
glibc Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-4046

Medium priority

Some fixes available 3 of 8

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Vulnerable Vulnerable
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-4438

Medium priority

Some fixes available 1 of 3

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Not affected Fixed Not affected Not affected Not affected
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-4437

Medium priority

Some fixes available 1 of 3

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server,...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Not affected Fixed Not affected Not affected Not affected
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-3904

Medium priority
Not affected

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release
glibc Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-0577

Medium priority
Not affected

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release Not in release
glibc Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-15281

Medium priority

Some fixes available 7 of 8

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release Not in release
glibc Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-0915

Medium priority

Some fixes available 7 of 8

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release Not in release
glibc Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-0861

Medium priority

Some fixes available 4 of 5

Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release
glibc Fixed Fixed Fixed Not affected
Show less packages