GNU vulnerabilities
13 CVEs tracked
GNU represents core Linux/Unix utilities and the development toolchain in our threat reports. The main themes observed are memory corruption (heap-based buffer overflow, out-of-bounds write/read) triggered by specially crafted files (e.g., fonts, XCOFF, ELF) and environment manipulation. Specifically, CVE-2026-53910 (diffutils), CVE-2026-18220 (binutils), and CVE-2026-56391 (coreutils) require attention due to memory management flaws. Defenders should disable unused utilities, monitor processing of untrusted files, and promptly apply patches, especially for `diff3`, `uniq -w`, and Bison (CVE-2026-56389).
Azərbaycanca: GNU alətləri təhlükəsizlik hesabatlarımızda mərkəzi Linux/Unix utilitlərini və inkişaf zəncirini təmsil edir. Müşahidə olunan əsas mövzular xüsusi formatlı fayllar (məsələn, font, XCOFF, ELF) vasitəsilə yaddaşın pozulması (heap-based buffer overflow, out-of-bounds write/read) və mühit manipulyasiyasıdır. Xüsusilə CVE-2026-53910 (diffutils), CVE-2026-18220 (binutils) və CVE-2026-56391 (coreutils) yaddaş idarəetməsi zəiflikləri ilə bağlı diqqət tələb edir. Müdafiəçilər istifadə olunmamış utilitləri sıradan çıxarmalı, qeyri-adi fayl emalına nəzarət etməli və xüsusilə `diff3`, `uniq -w` və Bison (CVE-2026-56389) üçün yamaları operativ tətbiq etməlidir.
This vendor's CVEs13
- CVE-2026-71394EPSS 0.28%
- CVE-2026-71393EPSS 0.39%
- CVE-2026-71392EPSS 0.39%
- CVE-2026-66486EPSS 0.14%
- CVE-2026-66485EPSS 0.13%
- CVE-2026-56391EPSS 0.13%
- CVE-2026-56389EPSS 0.16%
- CVE-2026-53910EPSS 0.33%
- CVE-2026-18477EPSS 0.08%
- CVE-2026-18220EPSS 0.30%
- CVE-2026-15003EPSS 0.11%
- CVE-2026-6390EPSS 0.15%
- CVE-2026-6368EPSS 0.11%
This hub is built from skopnix's own reporting on GNU: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.