Search: "gnu"

1221 CVEs found

CVE-2025-69648
6.2 MEDIUM

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes re...

Published: 2026-03-09
Products: 1
Vendors:
gnu

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag check...

Published: 2026-03-11
Products: 1
Vendors:
openclaw
CVE-2026-3904
6.2 MEDIUM

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on i...

Published: 2026-03-11
Products: 1
Vendors:
gnu

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in...

Published: 2026-03-12
Products: 9
Vendors:
python
CVE-2026-32746
9.8 CRITICAL

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

Published: 2026-03-13
Products: 1
Vendors:
gnu

telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.

Published: 2026-03-16
Products: 1
Vendors:
gnu
CVE-2026-3441
6.1 MEDIUM

A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By co...

Published: 2026-03-16
Products: 7
Vendors:
redhat gnu
CVE-2026-3442
6.1 MEDIUM

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing...

Published: 2026-03-16
Products: 7
Vendors:
redhat gnu
CVE-2026-32766
5.3 MEDIUM

astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX extensions were silently skipped when parsing tar archives. This silent skipping ...

Published: 2026-03-20
Products: 1
Vendors:
astral

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from ...

Published: 2026-03-20
Products: 1
Vendors:
gnu
CVE-2026-4438
5.4 MEDIUM

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostn...

Published: 2026-03-20
Products: 1
Vendors:
gnu
CVE-2026-4647
6.1 MEDIUM

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF objec...

Published: 2026-03-23
Products: 7
Vendors:
redhat gnu

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. In versions prior to 0.12.3 and 0.13.0, code for client certificate verification imported the certificate chain sent by the client into a f...

Published: 2026-03-24
Products: 1
Vendors:
mod_gnutls_project
CVE-2026-33308
6.8 MEDIUM

Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Prior to version 0.13.0, code for client certificate verification did not check the key purpose as set in the Extended Key Usage extension....

Published: 2026-03-24
Products: 1
Vendors:
mod_gnutls_project

Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based buffer overflow vulnerability in the Zen C compiler allows attackers to cause a...

Published: 2026-03-26
Products: 1
Vendors:
zenc-lang

The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remote...

Published: 2026-03-30
Products: 1
Vendors:
gnu
CVE-2026-32288
5.5 MEDIUM

tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded in the "old GNU sparse map" format.

Published: 2026-04-08
Products: 2
Vendors:
golang

A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value durin...

Published: 2026-04-09
Products: 2
Vendors:
redhat gnu
CVE-2026-5450
9.8 CRITICAL

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 coul...

Published: 2026-04-20
Products: 1
Vendors:
gnu

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version...

Published: 2026-04-20
Products: 1
Vendors:
gnu