These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability in the GNU C Library's DNS stub resolver can cause an assertion failure and process abortion when resolving names with a search list containing a domain of roughly 200 characters or more. This issue affects systems using GNU C Library versions 2.26 to 2.44, particularly those exposed to untrusted networks or receiving search domains from DHCP or VPN servers. The vulnerability can be trigge [truncated]
A GNU C Library converter vulnerability may cause applications to hang when converting crafted EUC_JISX0213 input. The vulnerability affects GNU C Library versions 2.3 to 2.44 and is related to EUC_JISX0213 character set conversions. Defenders should assess exposure and verify output buffer handling in affected applications. The vulnerability may lead to denial-of-service attacks if exploited. The affecte [truncated]
A denial-of-service vulnerability exists in the GNU C Library versions 2.3 to 2.44, allowing attackers to cause hangs in applications using the library for SHIFT_JISX0213 input conversion to UCS-4 or internal wide character encoding. This occurs when crafted input splits two code points in the output buffer, causing an infinite loop. Defenders should assess exposure and prioritize patching, especially in [truncated]
A flaw in the GNU C Library's tdelete function may cause an application crash when processing a sufficiently deep tree. This issue affects GNU C Library versions 2.1 to 2.44. The vulnerability is triggered by a node at a depth of exactly 40 (or 40 plus a multiple of 20) in a tree with at least a million nodes. The written value is a pointer into a tree node and is not directly attacker controlled. Defende [truncated]
The GNU C Library versions 2.38 to 2.44 have a vulnerability in the strfmon and strfmon_l functions. These functions can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. This issue requires specific conditions to be exploitable, such as an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination [truncated]
A vulnerability in the GNU C Library's nscd service can cause a stack overflow, leading to a crash and potential performance degradation in DNS resolution. This issue requires the nscd service to be enabled and using an untrusted DNS server. The vulnerability is caused by the nscd service's inability to handle large DNS responses, which can lead to a stack overflow and crash the service. The impact of thi [truncated]
CVE-2026-6238 is a vulnerability in the GNU C Library's deprecated functions ns_printrrf, ns_printrr, and fp_nquery. These functions, used for application debugging, fail to validate RDATA content against the RDATA length in DNS responses for A6, CERT, LOC, TKEY, or TSIG records. This oversight may allow an attacker to craft a malicious DNS response, potentially causing a target application to crash or re [truncated]
The GNU C Library versions 2.2 and newer contain a vulnerability due to the deprecated functions ns_printrrf, ns_printrr, and fp_nquery failing to enforce the caller-supplied buffer length. This can result in an out-of-bounds write when printing TSIG records. The vulnerability has a CVSS score of 7.3 and is classified as HIGH. Affected product deployments should be identified, and owners assigned for foll [truncated]
CVE-2026-5928 is a HIGH severity vulnerability in the GNU C Library version 2.43 or earlier. The ungetwc function may result in an attempt to read bytes before an allocated buffer, potentially leading to unintentional disclosure of neighboring data in the heap or a program crash. This vulnerability affects systems using the GNU C Library, particularly those with specific character encoding configurations. [truncated]
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them. Affected systems may experience crashes or instability. Users should verify the presence of these char [truncated]
A vulnerability was found in the GNU C library version 2.34 to version 2.43. Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification. This issue arises from the library's handling of DNS responses. The vulnerability has a CVSS score of 5.4 and [truncated]
The GNU C Library (glibc) versions 2.34 to 2.43 are vulnerable to a HIGH severity issue, CVE-2026-4437, which could allow an attacker to cause an application to treat a non-answer section of a DNS response as a valid answer. This issue occurs when using the gethostbyaddr or gethostbyaddr_r functions with a crafted response from a configured DNS server. The vulnerability has a CVSS score of 7.5 and is cons [truncated]