Debian Glibc vulnerabilities
145 known vulnerabilities affecting debian/glibc.
Total CVEs
145
CISA KEV
1
actively exploited
Public exploits
22
Exploited in wild
4
Severity breakdown
CRITICAL17HIGH42MEDIUM45LOW41
Vulnerabilities
Page 2 of 8
CVE-2022-23218P3CRITICALCVSS 9.8fixed in glibc 2.33-3 (bookworm)2022
CVE-2022-23218 [CRITICAL] CVE-2022-23218: glibc - The deprecated compatibility function svcunix_create in the sunrpc module of the...
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
debian
CVE-2022-23219P3CRITICALCVSS 9.8fixed in glibc 2.33-3 (bookworm)2022
CVE-2022-23219 [CRITICAL] CVE-2022-23219: glibc - The deprecated compatibility function clnt_create in the sunrpc module of the GN...
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
debian
CVE-2018-11236P3LOWCVSS 9.8fixed in glibc 2.27-4 (bookworm)2018
CVE-2018-11236 [CRITICAL] CVE-2018-11236: glibc - stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier...
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 2.27-4)
bullseye: resolve
debian
CVE-2017-1000409P3HIGHCVSS 7.8PoCfixed in glibc 2.25-5 (bookworm)2017
CVE-2017-1000409 [HIGH] CVE-2017-1000409: glibc - A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be trigg...
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
Scope: local
bookworm: resolved (fixed in 2.25-5)
bullseye: resolved (fixed in 2.25-5)
forky: resolved (fixed in 2.25-5)
sid:
debian
CVE-2014-9984P3CRITICALCVSS 9.8fixed in glibc 2.19-14 (bookworm)2014
CVE-2014-9984 [CRITICAL] CVE-2014-9984: glibc - nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not corr...
nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.
Scope: local
bookworm: resolved (fixed in 2.19-14)
bullseye: resolved (fixed in 2.19-14)
forky: resolved (fixed in 2.19-14)
debian
CVE-2024-33599P3HIGHCVSS 8.1fixed in glibc 2.36-9+deb12u7 (bookworm)2024
CVE-2024-33599 [HIGH] CVE-2024-33599: glibc - nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache D...
nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Sco
debian
CVE-2020-6096P3LOWCVSS 8.1fixed in glibc 2.31-2 (bookworm)2020
CVE-2020-6096 [HIGH] CVE-2020-6096: glibc - An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() impl...
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lea
debian
CVE-2009-4880P4LOWCVSS 7.5PoCfixed in glibc 2.11.1-1 (bookworm)2009
CVE-2009-4880 [HIGH] CVE-2009-4880: glibc - Multiple integer overflows in the strfmon implementation in the GNU C Library (a...
Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format function in PHP, a related issue to CVE-2008-1391.
Scope
debian
CVE-2017-15670P3LOWCVSS 9.8fixed in glibc 2.25-3 (bookworm)2017
CVE-2017-15670 [CRITICAL] CVE-2017-15670: glibc - The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error ...
The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories using the ~ operator followed by a long string.
Scope: local
bookworm: resolved (fixed in 2.25-3)
bullseye: resolved (fixed in 2.25-3)
forky: resolved (fixed in 2.25-3)
debian
CVE-2015-8779P3CRITICALCVSS 9.8fixed in glibc 2.21-7 (bookworm)2015
CVE-2015-8779 [CRITICAL] CVE-2015-8779: glibc - Stack-based buffer overflow in the catopen function in the GNU C Library (aka gl...
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.
Scope: local
bookworm: resolved (fixed in 2.21-7)
bullseye: resolved (fixed in 2.21-7)
forky: resolved (fixed in 2.21-
debian
CVE-2017-18269P3CRITICALCVSS 9.8fixed in glibc 2.27-3 (bookworm)2017
CVE-2017-18269 [CRITICAL] CVE-2017-18269: glibc - An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch...
An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclo
debian
CVE-2026-0861P3HIGHCVSS 8.4fixed in glibc 2.42-8 (forky)2026
CVE-2026-0861 [HIGH] CVE-2026-0861: glibc - Passing too large an alignment to the memalign suite of functions (memalign, pos...
Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able t
debian
CVE-1999-0199P3CRITICALCVSS 9.8fixed in glibc 2.2-1 (bookworm)1999
CVE-1999-0199 [CRITICAL] CVE-1999-0199: glibc - manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement...
manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999.
Scope: local
bookworm: resolved (fixed in 2.2-1)
bullseye: resolved (fix
debian
CVE-2023-6779P3HIGHCVSS 8.2fixed in glibc 2.36-9+deb12u4 (bookworm)2023
CVE-2023-6779 [HIGH] CVE-2023-6779: glibc - An off-by-one heap-based buffer overflow was found in the __vsyslog_internal fun...
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash.
debian
CVE-2017-15804P3LOWCVSS 9.8fixed in glibc 2.25-3 (bookworm)2017
CVE-2017-15804 [CRITICAL] CVE-2017-15804: glibc - The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.2...
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.
Scope: local
bookworm: resolved (fixed in 2.25-3)
bullseye: resolved (fixed in 2.25-3)
forky: resolved (fixed in 2.25-3)
sid: resolved (fixed in 2.25-3)
trixie: resolved (fixed in 2.25-3)
debian
CVE-2005-3590P3CRITICALCVSS 9.8fixed in glibc 2.3.5-3 (bookworm)2005
CVE-2005-3590 [CRITICAL] CVE-2005-3590: glibc - The getgrouplist function in the GNU C library (glibc) before version 2.3.5, whe...
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory.
Scope: local
bookworm: resolved (fixed in 2.3.5-3)
bullseye: resolved (fixed in 2.3.5-3)
forky: resolv
debian
CVE-2012-3480P4MEDIUMCVSS 4.6PoCfixed in glibc 2.13-36 (bookworm)2012
CVE-2012-3480 [MEDIUM] CVE-2012-3480: glibc - Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strto...
Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
Scope: local
bookworm:
debian
CVE-2021-35942P3CRITICALCVSS 9.1fixed in glibc 2.31-13 (bookworm)2021
CVE-2021-35942 [CRITICAL] CVE-2021-35942: glibc - The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or ...
The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.
Scope
debian
CVE-2026-0915P3HIGHCVSS 7.5fixed in glibc 2.42-8 (forky)2026
CVE-2026-0915 [HIGH] CVE-2026-0915: glibc - Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec...
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.42-8)
sid: resolved (fixed in 2.4
debian
CVE-2015-8983P3HIGHCVSS 8.1fixed in glibc 2.21-1 (bookworm)2015
CVE-2015-8983 [HIGH] CVE-2015-8983: glibc - Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU...
Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to computing a size in bytes, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (f
debian