Debian Glibc vulnerabilities
145 known vulnerabilities affecting debian/glibc.
Total CVEs
145
CISA KEV
1
actively exploited
Public exploits
22
Exploited in wild
4
Severity breakdown
CRITICAL17HIGH42MEDIUM45LOW41
Vulnerabilities
Page 7 of 8
CVE-2025-8058P4MEDIUMCVSS 5.9fixed in glibc 2.36-9+deb12u13 (bookworm)2025
CVE-2025-8058 [MEDIUM] CVE-2025-8058: glibc - The regcomp function in the GNU C library version from 2.4 to 2.41 is subject t...
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architec
debian
CVE-2026-4438P4MEDIUMCVSS 5.4fixed in glibc 2.42-14 (forky)2026
CVE-2026-4438 [MEDIUM] CVE-2026-4438: glibc - Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that sp...
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.42-14)
sid: resolved (fixed
debian
CVE-2015-8985P4LOWCVSS 5.9fixed in glibc 2.28-1 (bookworm)2015
CVE-2015-8985 [MEDIUM] CVE-2015-8985: glibc - The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows con...
The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.
Scope: local
bookworm: resolved (fixed in 2.28-1)
bullseye: resolved (fixed in 2.28-1)
forky: resolved (fixed in 2.28-1)
sid: resol
debian
CVE-2015-8984P4MEDIUMCVSS 5.9fixed in glibc 2.21-1 (bookworm)2015
CVE-2015-8984 [MEDIUM] CVE-2015-8984: glibc - The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might...
The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 2.21-1)
bullseye: resolved (fixed in 2.21-1)
forky: resolved (fixed in 2.21-1)
sid: resolved (fixed i
debian
CVE-2013-0242P4LOWCVSS 5.0fixed in glibc 2.17-2 (bookworm)2013
CVE-2013-0242 [MEDIUM] CVE-2013-0242: glibc - Buffer overflow in the extend_buffers function in the regular expression matcher...
Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters.
Scope: local
bookworm: resolved (fixed in 2.17-2)
bullseye: resolved (fixed in 2.17-2)
forky: resolved (fi
debian
CVE-2020-27618P4MEDIUMCVSS 5.9fixed in glibc 2.31-5 (bookworm)2020
CVE-2020-27618 [MEDIUM] CVE-2020-27618: glibc - The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, w...
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.
Scope:
debian
CVE-2020-10029P4MEDIUMCVSS 5.5fixed in glibc 2.30-1 (bookworm)2020
CVE-2020-10029 [MEDIUM] CVE-2020-10029: glibc - The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack bu...
The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.
Scope: local
bookworm: resolved (fixed in 2
debian
CVE-2015-8777P4MEDIUMCVSS 5.5fixed in glibc 2.21-1 (bookworm)2015
CVE-2015-8777 [MEDIUM] CVE-2015-8777: glibc - The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or li...
The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding protection mechanism via a zero value of the LD_POINTER_GUARD environment variable.
Scope: local
bookworm: resolved (fixed in 2.21-1)
bullseye: resolved (fixed in 2.21-1)
forky: resolved (fixed in 2.21-1)
sid: resolved (fixed
debian
CVE-2020-29562P4MEDIUMCVSS 4.8fixed in glibc 2.31-7 (bookworm)2020
CVE-2020-29562 [MEDIUM] CVE-2020-29562: glibc - The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when ...
The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 2.31-7)
bullseye: resolved (fixed in 2.31-7)
forky: resolved (fixed in 2.31-7)
si
debian
CVE-2002-1146P4MEDIUMCVSS 5.0fixed in glibc 2.3 (bookworm)2002
CVE-2002-1146 [MEDIUM] CVE-2002-1146: glibc - The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as g...
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (crash).
Sco
debian
CVE-2013-4332P4MEDIUMCVSS 4.3fixed in glibc 2.17-93 (bookworm)2013
CVE-2013-4332 [MEDIUM] CVE-2013-4332: glibc - Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or...
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_memalign, (4) memalign, or (5) aligned_alloc functions.
Scope: local
bookworm: resolved (fixed in 2.17-93)
bullseye: resolve
debian
CVE-2019-7309P4LOWCVSS 5.5fixed in glibc 2.28-6 (bookworm)2019
CVE-2019-7309 [MEDIUM] CVE-2019-7309: glibc - In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for ...
In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.
Scope: local
bookworm: resolved (fixed in 2.28-6)
bullseye: resolved (fixed in 2.28-6)
forky: resolved (fixed in 2.28-6)
sid: resolved (fixed in 2.28-
debian
CVE-2011-5320P4MEDIUMCVSS 6.2fixed in glibc 2.15 (bookworm)2011
CVE-2011-5320 [MEDIUM] CVE-2011-5320: glibc - scanf and related functions in glibc before 2.15 allow local users to cause a de...
scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.
Scope: local
bookworm: resolved (fixed in 2.15)
bullseye: resolved (fixed in 2.15)
forky: resolved (fixed in 2.15)
sid: resolved (fixed in 2.15)
trixie: resolved (fixed in 2.15)
debian
CVE-2009-4881P4LOWCVSS 7.5fixed in glibc 2.11.1-1 (bookworm)2009
CVE-2009-4881 [HIGH] CVE-2009-4881: glibc - Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfm...
Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.
Scope: local
book
debian
CVE-2006-7254P4MEDIUMCVSS 5.5fixed in glibc 2.5-1 (bookworm)2006
CVE-2006-7254 [MEDIUM] CVE-2006-7254: glibc - The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close i...
The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a denial of service attack on the daemon.
Scope: local
bookworm: resolved (fixed in 2.5-1)
bullseye: resolved (fixed in 2.5-1)
forky: resolved (fixed in 2.5-1)
sid: resolved (fixed in 2.5-1)
t
debian
CVE-2011-1659P4MEDIUMCVSS 5.1fixed in glibc 2.13-8 (bookworm)2011
CVE-2011-1659 [MEDIUM] CVE-2011-1659: glibc - Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2....
Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.
Scope: local
bookworm: resolved (fixed in 2.13-8)
bullsey
debian
CVE-2015-20109P4MEDIUMCVSS 5.5fixed in glibc 2.22-1 (bookworm)2015
CVE-2015-20109 [MEDIUM] CVE-2015-20109: glibc - end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or li...
end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984
debian
CVE-2007-4840P4LOWCVSS 5.0fixed in glibc 2.7-1 (bookworm)2007
CVE-2007-4840 [MEDIUM] CVE-2007-4840: glibc - PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of se...
PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via (1) a long string in the out_charset parameter to the iconv function; or a long string in the charset parameter to the (2) iconv_mime_decode_headers, (3) iconv_mime_decode, or (4) iconv_strlen function. NOTE: this might not be a vulnerability in most web serve
debian
CVE-2019-19126P4LOWCVSS 3.3fixed in glibc 2.29-8 (bookworm)2019
CVE-2019-19126 [LOW] CVE-2019-19126: glibc - On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to i...
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
Scope: local
bookworm: resolved (fixed in 2.29-8)
debian
CVE-2004-1382P4LOWCVSS 2.1fixed in glibc 2.3.2.ds1-19 (bookworm)2004
CVE-2004-1382 [LOW] CVE-2004-1382: glibc - The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite a...
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
Scope: local
bookworm: resolved (fixed in 2.3.2.ds1-19)
bullseye: resolved (fixed in 2.3.2.ds1-19)
forky: resolved (fixed in 2.3.2.ds1-19)
sid: resolved (fixed in 2.3.2.ds1-19)
trixie: resolv
debian