- glibc-2.34-28.0.1.el9_0 ()
- 2.34-231.el9_7.10
- 2026-03-09 20:36:57
- CVE CVE-2023-4813, CVSSv2 Score: 5.9
- Description:
A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
- Patch: glibc/2.34/glibc-RHEL-2437.patch
- CVE CVE-2023-4806, CVSSv2 Score: 5.9
- Description:
A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the nss_gethostbyname2_r and nss_getcanonname_r hooks without implementing the nss*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.
- Patch: glibc/2.34/CVE-2023-4806-2.34-28.patch
- CVE CVE-2023-4911, CVSSv2 Score: 7.8
- Description:
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
- Patch: glibc/2.34/glibc-RHEL-2999.patch
- CVE CVE-2024-2961, CVSSv2 Score: 8.8
- Description:
iconv: ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence
- Patch: glibc/2.34/glibc-RHEL-32480.patch
- CVE CVE-2024-33599, CVSSv2 Score: 7.6
- Description:
nscd: Stack-based buffer overflow in netgroup cache
- Patch: glibc/2.34/glibc-RHEL-34318-1.patch
- CVE CVE-2024-33600, CVSSv2 Score: 5.3
- Description:
nscd: Null pointer crashes after notfound response
- Patch: glibc/2.34/glibc-RHEL-34318-2.patch
- CVE CVE-2024-33600, CVSSv2 Score: 5.3
- Description:
nscd: Null pointer crashes after notfound response
- Patch: glibc/2.34/glibc-RHEL-34318-3.patch
- CVE CVE-2024-33601 CVE-2024-33602, CVSSv2 Score: 4.0
- Description:
nscd: netgroup cache assumes NSS callback uses in-buffer strings
- Patch: glibc/2.34/glibc-RHEL-34318-4.patch
- CVE CVE-2025-0395, CVSSv2 Score: 5.5
- Description:
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
- Patch: glibc/2.34/glibc-RHEL-83294-1-backport_v40.patch
- CVE CVE-2025-0395, CVSSv2 Score: 5.5
- Description:
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
- Patch: glibc/2.34/glibc-RHEL-83294-2-backport_v40.patch
- CVE CVE-2025-0395, CVSSv2 Score: 5.5
- Description:
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
- Patch: glibc/2.34/glibc-RHEL-83294-3.patch
- CVE CVE-2025-8058, CVSSv2 Score: 4.2
- Description:
Double free in glibc
- Patch: glibc/2.34/CVE-2025-8058.patch
- CVE CVE-2026-0861, CVSSv2 Score: 9.8
- Description:
Integer overflow in memalign leads to heap corruption
- Patch: glibc/2.35/CVE-2026-0861.patch
- CVE CVE-2026-0915, CVSSv2 Score: 7.5
- Description:
getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler
- Patch: glibc/2.35/CVE-2026-0915.patch
- CVE CVE-2025-15281, CVSSv2 Score: 7.5
- Description:
wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
- Patch: glibc/2.34/glibc-RHEL-144079-1.patch
- CVE CVE-2025-15281, CVSSv2 Score: 7.5
- Description:
wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
- Patch: glibc/2.34/glibc-RHEL-144079-2.patch
- CVE CVE-2025-15281, CVSSv2 Score: 7.5
- Description:
Remove flaky tst-wordexp-reuse test from build
- Patch: glibc/2.34/glibc-RHEL-144079-3.patch