« Back to list

GNU

GNU C Library: vulnerabilities and CVEs

GNU C Library has 8 published vulnerabilities, 6 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs8
Last 12 months6
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-80489Medium (5.9)0.41%—Sep 15, 2026
Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the…
CVE-2026-77117Medium (5.9)0.41%—Sep 15, 2026
Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the…
CVE-2026-19542Medium (5.6)0.23%—Sep 14, 2026
Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete…
CVE-2026-19499High (7.7)0.30%—Sep 14, 2026
Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an…
CVE-2026-18374Medium (4.9)0.14%—Aug 27, 2026
Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string…
CVE-2026-6368Low (2.1)0.15%—Aug 10, 2026
Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
CVE-2025-8058Medium (5.9)0.19%—Jul 23, 2025
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that…
CVE-2025-0395Medium (6.2)0.36%—Jan 22, 2025
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by GNU