Search CVE reports
1 – 10 of 174 results
[Unknown description]
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| eglibc | Not in release | Not in release | Not in release | — | — |
[Out-of-bounds stack array access in tdelete]
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| eglibc | Not in release | Not in release | Not in release | — | — |
[Unknown description]
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| eglibc | Not in release | Not in release | Not in release | — | — |
When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username...
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| eglibc | Not in release | Not in release | Not in release | — | — |
Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| eglibc | Not in release | Not in release | Not in release | — | — |
Some fixes available 3 of 8
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or...
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Fixed | Fixed | Fixed | Vulnerable | Vulnerable |
| eglibc | Not in release | Not in release | Not in release | — | — |
Some fixes available 3 of 8
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Fixed | Fixed | Fixed | Vulnerable | Vulnerable |
| eglibc | Not in release | Not in release | Not in release | — | — |
Some fixes available 3 of 8
Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result...
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Fixed | Fixed | Fixed | Needs evaluation | Needs evaluation |
| eglibc | Not in release | Not in release | Not in release | — | — |
Some fixes available 3 of 8
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap...
2 affected packages
glibc, eglibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| glibc | Fixed | Fixed | Fixed | Needs evaluation | Needs evaluation |
| eglibc | Not in release | Not in release | Not in release | — | — |
Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API...
2 affected packages
eglibc, glibc
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| eglibc | Not in release | Not in release | Not in release | — | — |
| glibc | Not affected | Not affected | Not affected | Not affected | Not affected |