Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

glibc — Vulnerabilities & Security Advisories 32

All 32 CVE vulnerabilities found in glibc, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the GNU C Library (glibc), a core component of most Linux distributions, categorized by Common Weakness Enumeration (CWE) tags and associated with the GNU project vendor. It collects reported security flaws ranging from code injection and buffer overflows to privilege escalation and information disclosure, covering incidents identified from early 2000s through to current public disclosures. Visitors can track vendor advisories issued by the GNU project, understand the prevalence and impact of specific weakness classes within this foundational system library, and look up a product’s vulnerability history to assess long-term security trends. The resource organizes findings by severity, release impact, and fix availability, enabling developers and security analysts to prioritize remediation efforts and review historical patterns of exploitation. By consolidating diverse sources including CVE entries, patch notes, and security bulletins, this aggregation offers a comprehensive view of the threat landscape affecting glibc. Users can filter results by specific CWE identifiers or examine the chronological evolution of defects in the library. This approach supports informed decision-making regarding system updates and configuration hardening without requiring manual cross-referencing of multiple repositories. The page serves as a centralized reference for understanding how systemic flaws in the C library propagate across the software supply chain. It highlights recurring issues such as integer overflows and race conditions that have historically impacted system stability and confidentiality. All data is structured to facilitate efficient search and analysis for both automated tools and manual review processes.

Vendor: GNU C Library

CVE IDTitleCVSSSeverityPublished
CVE-2026-6238 Buffer overread in ns_printrrf with corrupted RDATA field CWE-126 8.2AIHighAI2026-04-28
CVE-2026-5435 Potential buffer overflow in ns_sprintrrf TSIG handling path CWE-787 9.8AICriticalAI2026-04-28
CVE-2026-5450 scanf %mc off-by-one heap buffer overflow CWE-122 9.8AICriticalAI2026-04-20
CVE-2026-5928 Potential buffer under-read in ungetwc CWE-127 9.1AICriticalAI2026-04-20
CVE-2026-4046 iconv crash due to assertion failure with untrusted input CWE-617 7.5 -2026-03-30
CVE-2026-4438 gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames CWE-20 4.3 -2026-03-20
CVE-2026-4437 gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response CWE-125 7.5 -2026-03-20
CVE-2026-3904 GNU C Library 安全漏洞 CWE-366 6.8AIMediumAI2026-03-11
CVE-2025-15281 wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory CWE-908 7.5AIHighAI2026-01-20
CVE-2026-0915 getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler CWE-908 7.5AIHighAI2026-01-15
CVE-2026-0861 Integer overflow in memalign leads to heap corruption CWE-190 9.8AICriticalAI2026-01-14
CVE-2025-8058 GNU C Library 安全漏洞 CWE-415 9.8 -2025-07-23
CVE-2025-5745 GNU C Library 安全漏洞 9.4 -2025-06-05
CVE-2025-5702 GNU C Library 安全漏洞 9.4 -2025-06-05
CVE-2025-4802 GNU C Library 安全漏洞 CWE-426 7.5AIHighAI2025-05-16
CVE-2025-0395 GNU C Library 安全漏洞 CWE-131 9.8 -2025-01-22
CVE-2024-33602 nscd: netgroup cache assumes NSS callback uses in-buffer strings CWE-466 8.4 -2024-05-06
CVE-2024-33601 nscd: netgroup cache may terminate daemon on memory allocation failure CWE-617 6.2 -2024-05-06
CVE-2024-33600 nscd: Null pointer crashes after notfound response CWE-476 7.5 -2024-05-06
CVE-2024-33599 nscd: Stack-based buffer overflow in netgroup cache CWE-121 9.8AICriticalAI2024-05-06
CVE-2024-2961 GNU C Library 安全漏洞 CWE-787 9.1AICriticalAI2024-04-17
CVE-2023-6780 Glibc: integer overflow in __vsyslog_internal() CWE-131 5.3 Medium2024-01-31
CVE-2023-6779 Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal() CWE-122 8.2 High2024-01-31
CVE-2023-6246 Glibc: heap-based buffer overflow in __vsyslog_internal() CWE-122 8.4 High2024-01-31
CVE-2021-3999 glibc 安全漏洞 CWE-193 7.8 -2022-08-24
CVE-2021-3998 glibc 缓冲区错误漏洞 CWE-125 6.2 -2022-08-24
CVE-2020-1752 GNU C Library 资源管理错误漏洞 CWE-416 7.0 High2020-04-30
CVE-2020-1751 GNU C Library 缓冲区错误漏洞 CWE-787 5.1 Medium2020-04-17
CVE-2019-1010025 GNU C Library 安全特征问题漏洞 5.3 -2019-07-15
CVE-2019-1010023 GNU C Library 权限许可和访问控制问题漏洞 8.8 -2019-07-15

All 32 known CVE vulnerabilities affecting glibc with full Chinese analysis, references, and POCs where available.