glibc
The GNU C Library- Software type
- —
- Catalog vulnerabilities
- 25
Severity across 1 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 1 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 25 vulnerability records affecting glibc.
Among the 1 records analyzed by CyStack, 0 are High or Critical and 0 appear in the CISA KEV catalog.
Compare the version you run with each vulnerability and the provider guidance below. The data only includes records analyzed so far.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-89092Stack overflow in nscd due to unbounded alloca use | Exploitation statusNot confirmed | FixYes | Published09/11/2026 | SeverityMedium |
CVE-2026-18374CVE-2026-18374 | Exploitation statusNot known exploited | FixYes | Published08/27/2026 | SeverityMedium |
CVE-2026-6791Potential stack-based buffer clash during tilde expansion in wordexp | Exploitation statusNot known exploited | FixYes | Published08/10/2026 | SeverityMedium |
CVE-2026-6238Buffer overread in ns_printrrf with corrupted RDATA field | Exploitation statusNot known exploited | FixNot confirmed | Published04/28/2026 | SeverityMedium |
CVE-2026-5435Potential buffer overflow in ns_sprintrrf TSIG handling path | Exploitation statusNot known exploited | FixNot confirmed | Published04/28/2026 | SeverityHigh |
CVE-2026-5450scanf %mc off-by-one heap buffer overflow | Exploitation statusPublic exploit | FixNot confirmed | Published04/20/2026 | SeverityCritical |
CVE-2026-5928Potential buffer under-read in ungetwc | Exploitation statusPublic exploit | FixYes | Published04/20/2026 | SeverityHigh |
CVE-2026-5358CVE-2026-5358 | Exploitation statusNot confirmed | FixNot confirmed | Published04/20/2026 | SeverityUnknown |
CVE-2026-4046iconv crash due to assertion failure with untrusted input | Exploitation statusPublic exploit | FixYes | Published03/30/2026 | SeverityHigh |
CVE-2026-4438gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityMedium |
CVE-2026-4437gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response | Exploitation statusNot known exploited | FixYes | Published03/20/2026 | SeverityHigh |
CVE-2026-3904CVE-2026-3904 | Exploitation statusNot known exploited | FixYes | Published03/11/2026 | SeverityMedium |
CVE-2025-15281wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory | Exploitation statusNot known exploited | FixYes | Published01/20/2026 | SeverityHigh |
CVE-2026-0915getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler | Exploitation statusPublic exploit | FixYes | Published01/15/2026 | SeverityHigh |
CVE-2026-0861Integer overflow in memalign leads to heap corruption | Exploitation statusNot known exploited | FixYes | Published01/14/2026 | SeverityHigh |
CVE-2025-8058CVE-2025-8058 | Exploitation statusNot known exploited | FixYes | Published07/23/2025 | SeverityMedium |
CVE-2025-5745CVE-2025-5745 | Exploitation statusPublic exploit | FixNot confirmed | Published06/05/2025 | SeverityMedium |
CVE-2025-5702CVE-2025-5702 | Exploitation statusPublic exploit | FixNot confirmed | Published06/05/2025 | SeverityMedium |
CVE-2025-4802CVE-2025-4802 | Exploitation statusNot known exploited | FixYes | Published05/16/2025 | SeverityHigh |
CVE-2025-0395CVE-2025-0395 | Exploitation statusPublic exploit | FixYes | Published01/22/2025 | SeverityMedium |
CVE-2024-33602nscd: netgroup cache assumes NSS callback uses in-buffer strings | Exploitation statusNot known exploited | FixYes | Published05/06/2024 | SeverityHigh |
CVE-2024-33601nscd: netgroup cache may terminate daemon on memory allocation failure | Exploitation statusNot known exploited | FixYes | Published05/06/2024 | SeverityHigh |
CVE-2024-33600nscd: Null pointer crashes after notfound response | Exploitation statusNot known exploited | FixYes | Published05/06/2024 | SeverityMedium |
CVE-2024-33599nscd: Stack-based buffer overflow in netgroup cache | Exploitation statusNot known exploited | FixYes | Published05/06/2024 | SeverityHigh |
CVE-2024-2961CVE-2024-2961 | Exploitation statusPublic exploit | FixYes | Published04/17/2024 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan