Vulnerabilidades en The GNU C Library
31 resultadosAnálisis Vexday
A GNU C Library apresenta 21 vulnerabilidades catalogadas, com apenas 1 crítica e nenhuma sob exploração ativa conhecida, reduzindo significativamente o risco imediato. As 2 vulnerabilidades publicadas nos últimos 90 dias indicam descobertas contínuas, predominantemente relacionadas a CWE-617 (Reachable Assertion), típicas de falhas lógicas em verificação de entrada. O perfil sugere exposição moderada que requer monitoramento regular, mas sem urgência emergencial.
CVE-2025-5702MEDIUMThe strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to EPSS 0.3%CVE-2026-19499HIGHBuffer overflow in strfmon and strfmon_l right-justification paddingEPSS 0.3%CVE-2026-89092MEDIUMStack overflow in nscd due to unbounded alloca useEPSS 0.3%CVE-2025-5745MEDIUMThe strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 toEPSS 0.3%CVE-2026-4438MEDIUMgethostbyaddr and gethostbyaddr_r return invalid DNS hostnamesEPSS 0.3%CVE-2026-19542MEDIUMStack-based out-of-bounds write in tdelete during tree rebalancingEPSS 0.2%CVE-2025-8058MEDIUMThe regcomp function in the GNU C library version from 2.4 to 2.41 is
subject to a double free if some previous allocation fails. It can beEPSS 0.2%CVE-2026-3904MEDIUMCalling NSS-backed functions that support caching via nscd may call the
nscd client side code and in the GNU C Library version 2.36 under hEPSS 0.2%CVE-2026-18374MEDIUMPassing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library versioEPSS 0.1%CVE-2026-95818LOWAT_SECURE program buffer overflow via $ORIGIN processingEPSS 0.1%CVE-2026-86805MEDIUMAT_SECURE programs may load attacker-controlled code via $ORIGINEPSS 0.1%