Debian Glibc vulnerabilities
145 known vulnerabilities affecting debian/glibc.
Total CVEs
145
CISA KEV
1
actively exploited
Public exploits
22
Exploited in wild
4
Severity breakdown
CRITICAL17HIGH42MEDIUM45LOW41
Vulnerabilities
Page 3 of 8
CVE-2015-8778P3CRITICALCVSS 9.8fixed in glibc 2.21-8 (bookworm)2015
CVE-2015-8778 [CRITICAL] CVE-2015-8778: glibc - Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows co...
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.
Scope: local
bookworm: resolved (fixed in 2.21-8)
bullseye: resolved (fixed in
debian
CVE-2014-9761P3CRITICALCVSS 9.8fixed in glibc 2.23-1 (bookworm)2014
CVE-2014-9761 [CRITICAL] CVE-2014-9761: glibc - Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) ...
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.
Scope: local
bookworm: resolved (fixed in 2.23-1)
bullseye: resolved (fixed in 2.23-1)
for
debian
CVE-2019-9169P3CRITICALCVSS 9.8fixed in glibc 2.28-9 (bookworm)2019
CVE-2019-9169 [CRITICAL] CVE-2019-9169: glibc - In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in pos...
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
Scope: local
bookworm: resolved (fixed in 2.28-9)
bullseye: resolved (fixed in 2.28-9)
forky: resolved (fixed in 2.28-9)
sid: resolved (fixed in 2.28-9)
trixie: resolved (fixed in 2
debian
CVE-2018-6485P3CRITICALCVSS 9.8fixed in glibc 2.27-1 (bookworm)2018
CVE-2018-6485 [CRITICAL] CVE-2018-6485: glibc - An integer overflow in the implementation of the posix_memalign in memalign func...
An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.
Scope: local
bookworm: resolved (fixed in 2.27-1)
bullseye: resolved (fixed in 2.27-1)
forky: resolve
debian
CVE-2021-33574P3CRITICALCVSS 9.8fixed in glibc 2.32-1 (bookworm)2021
CVE-2021-33574 [CRITICAL] CVE-2021-33574: glibc - The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 h...
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Scope: local
bookworm: resolved (fixe
debian
CVE-2008-0122P3LOWCVSS 10.0fixed in glibc 2.2-1 (bookworm)2008
CVE-2008-0122 [CRITICAL] CVE-2008-0122: bind9 - Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and e...
Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
debian
CVE-2015-8982P3HIGHCVSS 8.1fixed in glibc 2.21-1 (bookworm)2015
CVE-2015-8982 [HIGH] CVE-2015-8982: glibc - Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc...
Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.21-1)
bullseye: resolved (fixed in 2.21-1)
forky: resolved (f
debian
CVE-2021-43396P3LOWCVSS 7.5fixed in glibc 2.32-5 (bookworm)2021
CVE-2021-43396 [HIGH] CVE-2021-43396: glibc - In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attac...
In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to b
debian
CVE-2003-0028P3CRITICALCVSS 9.8fixed in dietlibc 0.22-2 (bookworm)2003
CVE-2003-0028 [CRITICAL] CVE-2003-0028: dietlibc - Integer overflow in the xdrmem_getbytes() function, and possibly other functions...
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
Scope: local
bookworm: resol
debian
CVE-2014-9402P3HIGHCVSS 7.8fixed in glibc 2.19-14 (bookworm)2014
CVE-2014-9402 [HIGH] CVE-2014-9402: glibc - The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2...
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
Scope: local
bookworm: resolved (fixed in 2.19-14)
bullseye: resolved (fixed
debian
CVE-2018-19591P3HIGHCVSS 7.5fixed in glibc 2.28-1 (bookworm)2018
CVE-2018-19591 [HIGH] CVE-2018-19591: glibc - In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a ...
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
Scope: local
bookworm: resolved (fixed in 2.28-1)
bullseye: resolved (fixed in 2.28-1)
forky: resolved (fixed in 2.28-1)
sid: resolved (fi
debian
CVE-2020-29573P3HIGHCVSS 7.5fixed in glibc 2.23-1 (bookworm)2020
CVE-2020-29573 [HIGH] CVE-2020-29573: glibc - sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on...
sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to sprintf. NOTE: the issue does not affect glibc by default
debian
CVE-2021-3999P3HIGHCVSS 7.8fixed in glibc 2.33-4 (bookworm)2021
CVE-2021-3999 [HIGH] CVE-2021-3999: glibc - A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd...
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and escalate their privileges on the system.
Scope: local
boo
debian
CVE-2024-33601P3HIGHCVSS 7.3fixed in glibc 2.36-9+deb12u7 (bookworm)2024
CVE-2024-33601 [HIGH] CVE-2024-33601: glibc - nscd: netgroup cache may terminate daemon on memory allocation failure The Name...
nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability
debian
CVE-2026-4437P3HIGHCVSS 7.5fixed in glibc 2.42-14 (forky)2026
CVE-2026-4437 [HIGH] CVE-2026-4437: glibc - Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that sp...
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.
S
debian
CVE-2015-8776P3CRITICALCVSS 9.1fixed in glibc 2.21-7 (bookworm)2015
CVE-2015-8776 [CRITICAL] CVE-2015-8776: glibc - The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allo...
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
Scope: local
bookworm: resolved (fixed in 2.21-7)
bullseye: resolved (fixed in 2.21-7)
forky: resolved (fixed in 2.21-7)
sid: resolved
debian
CVE-2018-6551P3CRITICALCVSS 9.8fixed in glibc 2.27-1 (bookworm)2018
CVE-2018-6551 [CRITICAL] CVE-2018-6551: glibc - The malloc implementation in the GNU C Library (aka glibc or libc6), from versio...
The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap corruption.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2016-3075P3HIGHCVSS 7.5fixed in glibc 2.22-6 (bookworm)2016
CVE-2016-3075 [HIGH] CVE-2016-3075: glibc - Stack-based buffer overflow in the nss_dns implementation of the getnetbyname fu...
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
Scope: local
bookworm: resolved (fixed in 2.22-6)
bullseye: resolved (fixed in 2.22-6)
forky: resolved (fixed in 2.22-6)
debian
CVE-2024-33602P3HIGHCVSS 7.4fixed in glibc 2.36-9+deb12u7 (bookworm)2024
CVE-2024-33602 [HIGH] CVE-2024-33602: glibc - nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Servi...
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Scope: local
bookworm: resolved
debian
CVE-2016-3706P3MEDIUMCVSS 5.0fixed in glibc 2.22-8 (bookworm)2016
CVE-2016-3706 [MEDIUM] CVE-2016-3706: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
Scope: local
bookworm: resolved (fixed in 2.22-8)
bullseye
debian