Debian Glibc vulnerabilities
145 known vulnerabilities affecting debian/glibc.
Total CVEs
145
CISA KEV
1
actively exploited
Public exploits
22
Exploited in wild
4
Severity breakdown
CRITICAL17HIGH42MEDIUM45LOW41
Vulnerabilities
Page 6 of 8
CVE-2025-5745P4LOWCVSS 5.6fixed in glibc 2.41-9 (forky)2025
CVE-2025-5745 [MEDIUM] CVE-2025-5745: glibc - The strncmp implementation optimized for the Power10 processor in the GNU C Libr...
The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking
debian
CVE-2014-8121P4LOWCVSS 5.0fixed in glibc 2.21-1 (bookworm)2014
CVE-2014-8121 [MEDIUM] CVE-2014-8121: glibc - DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Lib...
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers the file pointer to be reset.
Scope: local
bookworm
debian
CVE-2013-4458P4LOWCVSS 5.0fixed in glibc 2.18-1 (bookworm)2013
CVE-2013-4458 [MEDIUM] CVE-2013-4458: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-201
debian
CVE-2017-12132P4MEDIUMCVSS 5.9fixed in glibc 2.25-1 (bookworm)2017
CVE-2017-12132 [MEDIUM] CVE-2017-12132: glibc - The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2...
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Scope: local
bookworm: resolved (fixed in 2.25-1)
bullseye: resolved (fixed in 2.25-1)
forky: resolved (fixed in 2.25-1)
s
debian
CVE-2013-1914P4LOWCVSS 5.0fixed in glibc 2.17-2 (bookworm)2013
CVE-2013-1914 [MEDIUM] CVE-2013-1914: glibc - Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddr...
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.17 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of domain conversion results.
Scope: local
bookworm: resolved (fixed in 2.17-2)
bullseye: resolved (f
debian
CVE-2014-7817P4MEDIUMCVSS 4.6fixed in glibc 2.19-14 (bookworm)2014
CVE-2014-7817 [MEDIUM] CVE-2014-7817: glibc - The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE...
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
Scope: local
bookworm: resolved (fixed in 2.19-14)
bullseye: resolved (fixed in 2.19-14)
forky: resolved (fixed in 2.19-14)
sid: resolved (fixed in 2.19-14
debian
CVE-2009-5064P4MEDIUMCVSS 6.9fixed in glibc 2.10.1-7 (bookworm)2009
CVE-2009-5064 [MEDIUM] CVE-2009-5064: glibc - ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local user...
ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary bina
debian
CVE-2012-4424P4LOWCVSS 5.1fixed in glibc 2.17-94 (bookworm)2012
CVE-2012-4424 [MEDIUM] CVE-2012-4424: glibc - Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glib...
Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a malloc failure and use of the alloca function.
Scope: local
bookworm: resolved (fixed in 2.17-94)
bullseye: resolved (fi
debian
CVE-2013-7424P4MEDIUMCVSS 5.1fixed in glibc 2.15-1 (bookworm)2013
CVE-2013-7424 [MEDIUM] CVE-2013-7424: glibc - The getaddrinfo function in glibc before 2.15, when compiled with libidn and the...
The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.
Scope: local
bookworm: resolved (fixed in 2.15-1)
bullseye: resolv
debian
CVE-2003-0689P4HIGHCVSS 7.5fixed in glibc 2.2.5 (bookworm)2003
CVE-2003-0689 [HIGH] CVE-2003-0689: glibc - The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers...
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.2.5)
bullseye: resolved (fixed in 2.2.5)
forky: resolved (fixed in 2.2.5)
sid: res
debian
CVE-2014-6040P4MEDIUMCVSS 5.0fixed in glibc 2.19-12 (bookworm)2014
CVE-2014-6040 [MEDIUM] CVE-2014-6040: glibc - GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to caus...
GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8.
Scope: local
bookworm: resolved (fixed in 2.19-12)
bullseye: resolved
debian
CVE-2007-3508P4LOWCVSS 7.2fixed in glibc 2.6-2 (bookworm)2007
CVE-2007-3508 [HIGH] CVE-2007-3508: glibc - Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2...
Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution
Scope: local
bookworm: resolved (fixed in 2.6-2)
bullseye: resolved (fix
debian
CVE-2012-3404P4LOWCVSS 5.0fixed in glibc 2.13-35 (bookworm)2012
CVE-2012-3404 [MEDIUM] CVE-2012-3404: glibc - The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka g...
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash) via a format string that uses positional parameters
debian
CVE-2012-3405P4LOWCVSS 5.0fixed in glibc 2.13-35 (bookworm)2012
CVE-2012-3405 [MEDIUM] CVE-2012-3405: glibc - The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka g...
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and crash) via a format string with a large number of format
debian
CVE-2016-10739P4MEDIUMCVSS 5.3fixed in glibc 2.28-6 (bookworm)2016
CVE-2016-10739 [MEDIUM] CVE-2016-10739: glibc - In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function...
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substr
debian
CVE-2026-3904P4MEDIUMCVSS 6.2fixed in glibc 2.36-9 (bookworm)2026
CVE-2026-3904 [MEDIUM] CVE-2026-3904: glibc - Calling NSS-backed functions that support caching via nscd may call the nscd cl...
Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently modified by other processes or threads and crash. The nscd client in the GNU C Library uses the memcmp function with inputs that may be concurre
debian
CVE-2017-15671P4LOWCVSS 5.9fixed in glibc 2.25-3 (bookworm)2017
CVE-2017-15671 [MEDIUM] CVE-2017-15671: glibc - The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.2...
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
Scope: local
bookworm: resolved (fixed in 2.25-3)
bullseye: resolved (fixed in 2.25-3)
forky: resolved (fix
debian
CVE-2011-1095P4MEDIUMCVSS 6.2fixed in glibc 2.13-16 (bookworm)2011
CVE-2011-1095 [MEDIUM] CVE-2011-1095: glibc - locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) bef...
locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.
Scope: local
bookworm: resolved (fixed in 2.13-16)
bullseye: resolved (fix
debian
CVE-2012-6656P4MEDIUMCVSS 5.0fixed in glibc 2.17-1 (bookworm)2012
CVE-2012-6656 [MEDIUM] CVE-2012-6656: glibc - iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-depen...
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.
Scope: local
bookworm: resolved (fixed in 2.17-1)
bullseye: resolved (fixed in 2.17-1)
forky: resolved (fixed in
debian
CVE-2025-0395P4MEDIUMCVSS 6.2fixed in glibc 2.36-9+deb12u10 (bookworm)2025
CVE-2025-0395 [MEDIUM] CVE-2025-0395: glibc - When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it ...
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
Scope: local
bookworm: resolved (fixed in 2.36-9+deb12u10)
bullseye: resolved (fixed in 2.31-13+deb11u12)
forky:
debian