Search CVE reports


Toggle filters

1 – 10 of 174 results


CVE-2026-77117

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-19542

Medium priority
Needs evaluation

[Out-of-bounds stack array access in tdelete]

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-19499

Medium priority
Needs evaluation

[Unknown description]

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-6791

Medium priority
Needs evaluation

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-6368

Medium priority
Needs evaluation

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-6238

Medium priority

Some fixes available 3 of 8

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Vulnerable Vulnerable
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-5435

Medium priority

Some fixes available 3 of 8

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Vulnerable Vulnerable
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-5928

Medium priority

Some fixes available 3 of 8

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-5450

Medium priority

Some fixes available 3 of 8

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap...

2 affected packages

glibc, eglibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
glibc Fixed Fixed Fixed Needs evaluation Needs evaluation
eglibc Not in release Not in release Not in release
Show less packages

CVE-2026-5358

Medium priority
Not affected

Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API...

2 affected packages

eglibc, glibc

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eglibc Not in release Not in release Not in release
glibc Not affected Not affected Not affected Not affected Not affected
Show less packages