GNU
GNU C Library: vulnerabilities and CVEs
GNU C Library has 8 published vulnerabilities, 6 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months6
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80489 | Medium (5.9) | 0.41% | — | Sep 15, 2026 | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the… |
| CVE-2026-77117 | Medium (5.9) | 0.41% | — | Sep 15, 2026 | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the… |
| CVE-2026-19542 | Medium (5.6) | 0.23% | — | Sep 14, 2026 | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete… |
| CVE-2026-19499 | High (7.7) | 0.30% | — | Sep 14, 2026 | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an… |
| CVE-2026-18374 | Medium (4.9) | 0.14% | — | Aug 27, 2026 | Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string… |
| CVE-2026-6368 | Low (2.1) | 0.15% | — | Aug 10, 2026 | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. |
| CVE-2025-8058 | Medium (5.9) | 0.19% | — | Jul 23, 2025 | The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that… |
| CVE-2025-0395 | Medium (6.2) | 0.36% | — | Jan 22, 2025 | When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.