Skip to content
Threat Feed

Vendor

Gnu

25 briefs RSS
high advisory

Multiple Vulnerabilities in GNU C Library

Multiple vulnerabilities in the GNU C Library (glibc) allow a local attacker to perform privilege escalation or trigger a denial of service condition on affected Linux-based systems.

glibc linux privilege-escalation denial-of-service
1t
medium advisory

Multiple Vulnerabilities in GNU Binutils

The GNU binutils package contains multiple vulnerabilities that allow a local attacker to cause a Denial of Service condition or disclose sensitive information by processing malformed object files.

binutils vulnerability local-exploitation
1t
low advisory

Stack-Based Buffer Overflow in GNU libextractor

GNU libextractor versions prior to 1.15 contain a stack-based buffer overflow in the process_star_office function that can be triggered by malicious OLE2 stream data to cause application crashes.

libextractor
1t 1c
critical threat

Authentication Bypass in GNU Inetutils Telnet Daemon (CVE-2026-24061)

An authentication bypass vulnerability in GNU Inetutils telnetd (CVE-2026-24061) allows unauthenticated remote attackers to gain root access via a malicious USER parameter.

Inetutils vulnerability cve telnet privilege-escalation remote-code-execution
1r 2t 1c
low advisory

Denial of Service Vulnerability in libtasn1

A vulnerability in the libtasn1 library tracked as CVE-2024-11111 allows a remote, anonymous attacker to cause a Denial of Service condition, potentially impacting applications that rely on the library for ASN.1 structure processing.

libtasn1
1c
high advisory

Remote Code Execution in GNU Debugger (GDB) via Malicious STABS Debug Data

A memory corruption vulnerability in GDB's STABS parser allows an attacker to achieve arbitrary code execution by providing a crafted ELF binary containing malicious debug sections.

GDB
1t 1c
high advisory

Privilege Escalation in Gnu C Library via CVE-2025-4802

A local privilege escalation vulnerability (CVE-2025-4802) in Gnu C Library (glibc) versions 2.27-2.38 allows attackers to gain root access by exploiting unsanitized LD_LIBRARY_PATH in statically linked setuid binaries.

Gnu C Library privilege-escalation linux cve-2025-4802
1t 1c
medium advisory

Multiple Vulnerabilities in GNU Screen

GNU screen contains multiple vulnerabilities that enable a local attacker to perform privilege escalation, data manipulation, or unauthorized information disclosure.

screen vulnerability privilege-escalation linux
1t
high advisory

Integer Overflow in GNU Emacs PBM/PPM/PGM Image Loader (CVE-2026-77219)

GNU Emacs versions prior to 31.0.91 are susceptible to an integer overflow vulnerability in the PBM/PPM/PGM image loader, potentially leading to heap memory disclosure.

Emacs +1 vulnerability command-injection local-exploitation
1t 1c updated
medium advisory

Denial of Service Vulnerability in GNU C Library

A local attacker can exploit a vulnerability in the GNU C Library (glibc) to cause application crashes or service instability, resulting in a Denial of Service.

PoC GNU C Library +2 denial-of-service linux vulnerability
1t 1c updated
medium advisory

Multiple Vulnerabilities in GNU Emacs

GNU Emacs is impacted by multiple vulnerabilities that can be leveraged by an attacker to facilitate information disclosure, arbitrary code execution, and denial-of-service.

Emacs vulnerability software-update
1t
medium advisory

Multiple Vulnerabilities in GNU cpio

Multiple vulnerabilities in the GNU cpio utility allow unauthenticated remote attackers to bypass security controls, cause denial of service, or manipulate data during file extraction.

cpio
1t 1c updated
high advisory

CVE-2026-18220: Out-of-Bounds Write in GNU Binutils BFD Library Leading to Arbitrary Code Execution

An out-of-bounds write vulnerability, CVE-2026-18220, exists in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils, allowing attackers to achieve arbitrary code execution via a specially crafted ELF/DLX object file processed by BFD-consuming tools.

binutils vulnerability code-execution linux
1t 1c
medium advisory

binutils: Vulnerability Enables Denial of Service and Data Disclosure

A local attacker can exploit a vulnerability in binutils to cause a Denial of Service condition and disclose sensitive data.

binutils linux macos denial-of-service data-disclosure vulnerability
2t
medium threat

CVE-2026-63825: gcov Utility Concurrent Access Crash Vulnerability

A vulnerability, CVE-2026-63825, has been disclosed for the 'gcov' utility, which is part of the GNU Compiler Collection, involving concurrent access crashes fixed by using atomic counter updates to ensure thread-safe operations, potentially leading to system instability or denial of service due to race conditions during data access.

exploited gcov vulnerability denial-of-service cve
1c
critical threat

Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector

The Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.

www.acosol.es +46 Qilin +1 ransomware double-extortion golang agriculture food-production
2r 13t 5c 178i updated
high advisory

CVE-2026-9605 Heap-Based Buffer Overflow in GNU libredwg

A heap-based buffer overflow vulnerability (CVE-2026-9605) exists in GNU libredwg up to version 0.13.4.8160 within the bit_read_RC function of the Dwgbmp Utility, potentially allowing a remote attacker to execute arbitrary code.

libredwg heap-based buffer overflow cve-2026-9605
2r 1c
high advisory

CVE-2026-5260: libgnutls Heap Overread via Short Premaster Secret

A remote attacker can trigger a heap overread in libgnutls by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, potentially leading to information disclosure.

libgnutls heap-overread information-disclosure tls cve
2r 1c
medium advisory

GNU libc Vulnerabilities Allow DNS Response Manipulation

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses, potentially leading to redirection to malicious sites.

libc dns spoofing glibc cache_poisoning
2r 1t
critical advisory

GNU InetUtils Multiple Vulnerabilities Allow Code Execution and Information Disclosure

Multiple vulnerabilities in GNU InetUtils allow a remote attacker to execute arbitrary code and disclose sensitive information.

InetUtils code-execution information-disclosure
2r 2t
medium advisory

GNU InetUtils Vulnerabilities Prior to 2.8

GNU released a security advisory addressing critical vulnerabilities in GNU InetUtils versions prior to 2.8, prompting users to apply necessary updates.

InetUtils vulnerability gnu
2r
medium advisory

Multiple Vulnerabilities in GNU libc

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary program code, cause a denial-of-service condition, or disclose sensitive information.

libc vulnerability glibc denial-of-service code-execution
2r 3t 5c
high advisory

GNU C Library iconv() Function Assertion Failure (CVE-2026-4046)

A vulnerability in the iconv() function of the GNU C Library (versions 2.43 and earlier) can cause a crash due to an assertion failure when handling IBM1390 or IBM1399 character sets, potentially leading to remote application denial-of-service.

The GNU C Library < 2.44 glibc iconv denial-of-service crash cve-2026-4046
2r 1t 3c updated
high advisory

GNUTLS RSA-PSK Authentication Bypass Vulnerability (CVE-2026-42010)

A vulnerability in GNUTLS (CVE-2026-42010) allows a remote attacker to bypass authentication on servers configured with RSA-PSK by sending a specially crafted username containing a NUL character, leading to unauthorized access.

gnutls authentication-bypass vulnerability
2r 1t 1c
critical advisory

GNU telnetd Buffer Overflow Vulnerability (CVE-2026-32746)

A critical buffer overflow vulnerability exists in GNU telnetd (CVE-2026-32746), potentially allowing remote code execution on affected Linux systems.

inetutils-telnetd cve-2026-32746 telnetd buffer-overflow linux
3r 2t 1c updated