VYPR

GNU C Library

by GNU

CVEs (2)

  • CVE-2026-19542MedSep 14, 2026
    risk 0.36cvss 5.6epss

    Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an explicit stack of parent nodes for…

  • CVE-2026-89092MedSep 11, 2026
    risk 0.27cvss 4.2epss 0.00

    The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled…