GNU C Library glibc

14 known vulnerabilities in GNU C Library glibc, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-97399 CVSS 3.7 low The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size…
  • CVE-2026-95818 CVSS 3.6 low A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local…
  • CVE-2026-86805 CVSS 6.3 medium A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through…
  • CVE-2026-8674 CVSS 5.3 medium Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a…
  • CVE-2026-80489 CVSS 5.9 medium Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library…
  • CVE-2026-77117 CVSS 5.9 medium Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library…
  • CVE-2026-19542 CVSS 5.6 medium Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an…
  • CVE-2026-19499 CVSS 7.7 high Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a…
  • CVE-2026-89092 CVSS 4.2 medium The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a…
  • CVE-2026-18374 CVSS 4.9 medium Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library…
  • CVE-2026-6791 CVSS 6.6 medium When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to…
  • CVE-2026-6238 CVSS 6.5 medium The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the…
  • CVE-2026-5435 CVSS 7.3 high The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the…
  • CVE-2026-5928 CVSS 7.5 high Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte…