ZeroHour
Product

glibc

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

The GNU C Library security advisories update for 2026-09-17

GNU C Library advisory describes a DNS stub resolver assertion failure that aborts processes when search domains reach roughly 200 characters in glibc 2.26-2.44.

GLIBC-SA-2026-0021 details an assertion failure in the glibc DNS stub resolver. Systems running glibc versions 2.26 through 2.44 abort when the search list in /etc/resolv.conf or the LOCALDOMAIN environment variable contains a domain of roughly 200 characters or more. The advisory was published as part of the GNU C Library security update batch on 2026-09-17.

oss-security · 23h agoVulnerability 2 sources

The GNU C Library security advisory update for 2026-09-10

glibc advisory GLIBC-SA-2026-0016: nscd can crash from a stack overflow when an untrusted DNS server returns oversized responses.

A new GNU C Library advisory (GLIBC-SA-2026-0016) describes a stack overflow in the nscd service caused by unbounded alloca use. glibc 2.3.4 and newer may crash when a malicious DNS server returns an oversized response, resulting in degraded DNS resolution. Exploitation requires nscd to be enabled and the system to be using an untrusted DNS server. The advisory was posted to oss-security by glibc maintainer Siddhesh Poyarekar.

oss-security · 7d agoVulnerability2

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.