the gnu project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting the gnu project.
- BDU:2026-06257Уязвимость утилиты factor пакета базовых утилит для операционных систем GNU Core Utilities, позволяющая нарушителю вызвать отказ в обслуживании5.5
- BDU:2026-06256Уязвимость пакета базовых утилит для операционных систем GNU Core Utilities, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании5.5
- BDU:2026-06230Уязвимость функции short_read() компонента buffer.c архиватора GNU Tar, связанная с чтением за допустимыми границами буфера данных, позволяющая нарушителю вызвать отказ в обслуживании3.7
- BDU:2026-06229Уязвимость функции _obstack_begin_worker() компонента obstack.cархиватора GNU Tar, позволяющая нарушителю вызвать отказ в обслуживании3.7
- BDU:2026-06212Уязвимость функции extract_file() архиватора GNU Tar, позволяющая нарушителю вызвать отказ в обслуживании3.1
- CVE-2025-15281wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory7.5
- CVE-2026-0861Integer overflow in memalign leads to heap corruption8.4
- CVE-2025-69194Wget2: arbitrary file write via metalink path traversal in gnu wget28.8
- CVE-2025-8058The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an ...4.2
- CVE-2025-45582GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to...4.1
- CVE-2025-52993A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix be...5.6
- CVE-2025-52992The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sand...3.2
- CVE-2025-52991The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into ...3.2
- CVE-2025-46416The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix throug...2.9
- CVE-2025-46415A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.9...3.2