rpm package
almalinux/glibc-langpack-syr
pkg:rpm/almalinux/glibc-langpack-syr
Vulnerabilities (9)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-6238 | Med | 6.5 | < 2.39-128.el10_2.alma.1 | 2.39-128.el10_2.alma.1 | Apr 28, 2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craf | |
| CVE-2026-5435 | Hig | 7.3 | < 2.39-128.el10_2.alma.1 | 2.39-128.el10_2.alma.1 | Apr 28, 2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records. | |
| CVE-2026-5928 | Hig | 7.5 | < 2.39-128.el10_2.alma.1 | 2.39-128.el10_2.alma.1 | Apr 20, 2026 | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buf | |
| CVE-2026-5450 | Cri | 9.8 | < 2.39-126.el10_2.alma.1 | 2.39-126.el10_2.alma.1 | Apr 20, 2026 | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow. | |
| CVE-2026-4046 | Hig | 7.5 | < 2.39-124.el10_2.alma.1 | 2.39-124.el10_2.alma.1 | Mar 30, 2026 | The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by rem | |
| CVE-2026-4438 | Med | 5.4 | < 2.39-121.el10_2.alma.1 | 2.39-121.el10_2.alma.1 | Mar 20, 2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification. | |
| CVE-2026-4437 | Hig | 7.5 | < 2.39-121.el10_2.alma.1 | 2.39-121.el10_2.alma.1 | Mar 20, 2026 | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that c | |
| CVE-2026-0915 | Hig | 7.5 | < 2.39-58.el10_1.7.alma.1 | 2.39-58.el10_1.7.alma.1 | Jan 15, 2026 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver. | |
| CVE-2026-0861 | Hig | 8.4 | < 2.39-58.el10_1.7.alma.1 | 2.39-58.el10_1.7.alma.1 | Jan 14, 2026 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control |
- affected < 2.39-128.el10_2.alma.1fixed 2.39-128.el10_2.alma.1
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craf
- affected < 2.39-128.el10_2.alma.1fixed 2.39-128.el10_2.alma.1
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
- affected < 2.39-128.el10_2.alma.1fixed 2.39-128.el10_2.alma.1
Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buf
- affected < 2.39-126.el10_2.alma.1fixed 2.39-126.el10_2.alma.1
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.
- affected < 2.39-124.el10_2.alma.1fixed 2.39-124.el10_2.alma.1
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets, which may be used to remotely crash an application. This vulnerability can be trivially mitigated by rem
- affected < 2.39-121.el10_2.alma.1fixed 2.39-121.el10_2.alma.1
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
- affected < 2.39-121.el10_2.alma.1fixed 2.39-121.el10_2.alma.1
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that c
- affected < 2.39-58.el10_1.7.alma.1fixed 2.39-58.el10_1.7.alma.1
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
- affected < 2.39-58.el10_1.7.alma.1fixed 2.39-58.el10_1.7.alma.1
Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control