Search CVE reports


Toggle filters

1 – 10 of 175 results


CVE-2026-95818

Medium priority
Needs evaluation

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-86805

Medium priority
Needs evaluation

A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-8674

Medium priority
Needs evaluation

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-89092

Medium priority
Vulnerable

The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-80489

Medium priority

Some fixes available 3 of 7

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-18374

Medium priority
Vulnerable

Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-77117

Medium priority

Some fixes available 3 of 7

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-19542

Medium priority

Some fixes available 3 of 7

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-19499

Medium priority
Fixed

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Not affected Not affected Not affected
eglibc Not in release Not in release Not in release — —
Show less packages

CVE-2026-6791

Medium priority

Some fixes available 3 of 7

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release — —
Show less packages