Vulnerabilities

GNU C Library on Linux: which version fixes what

glibc is linked into essentially every process on the system. That makes its advisories unusually far-reaching and its remediation unusually blunt: in practice you reboot.

SecAI tracks 169 distinct CVEs affecting GNU C Library across the 6 distributions below, of which 23 have no fixed package version on at least one of them. Each row names the package version that fixes it on that release.

What it is, and why it is on your server

The GNU C Library provides the basic system interfaces every program uses, from memory allocation to name resolution. It is packaged as libc6 on Debian and Ubuntu and glibc on Rocky and AlmaLinux.

Why its advisories behave the way they do

  • The reachable-from-anywhere flaws are the dangerous ones. The name resolution and printf paths are reached by code that never intended to handle untrusted input, which is what made Looney Tunables and the 2015 getaddrinfo bug so serious.
  • A restart list is not enough. So many processes link glibc that the practical answer after patching is a reboot, and a server that has not rebooted since the patch is still running the old library.
  • It is the package administrators most fear touching. A botched glibc upgrade can leave a machine unable to run anything, and that fear is why unpatched glibc lingers longer than almost anything else.

Check what you are actually running

The version that matters is the package version, not the upstream one. Distributions backport security fixes without changing the number before the dash, so a release that looks years old is frequently fully patched, and the revision after the dash is the only part that tells you.

Debian and Ubuntu
dpkg-query -W -f='${Package} ${Version}\n' libc6 libc-bin 2>/dev/null
Rocky Linux and AlmaLinux
rpm -q glibc glibc-common

Check how long it has been since the machine last rebooted with `uptime -s`. If that is older than the glibc package, the fix is on disk and not in memory.

Fixed versions, per distribution

Each distribution patches on its own schedule and under its own version scheme, so the same CVE has a different answer on each of them. These come from the distributions’ own advisory data, asked per release. Where a release has no fixed version, that is what the advisory says, not a gap in the data.

Ubuntu 22.04 LTSsource package: glibc

CVEPublishedFixed in package version
CVE-2026-868052026-09-22no fixed version released
CVE-2026-958182026-09-22no fixed version released
CVE-2026-86742026-09-17no fixed version released
CVE-2026-890922026-09-11no fixed version released
CVE-2026-194992026-09-082.35-0ubuntu3.15
CVE-2026-195422026-09-082.35-0ubuntu3.15
CVE-2026-63682026-09-082.35-0ubuntu3.15
CVE-2026-67912026-09-082.35-0ubuntu3.15
CVE-2026-771172026-09-082.35-0ubuntu3.15
CVE-2026-804892026-09-082.35-0ubuntu3.15
CVE-2026-183742026-08-27no fixed version released
CVE-2026-40462026-07-272.35-0ubuntu3.14
CVE-2026-44372026-07-272.35-0ubuntu3.14
CVE-2026-44382026-07-272.35-0ubuntu3.14
CVE-2026-54352026-07-272.35-0ubuntu3.14
CVE-2026-54502026-07-272.35-0ubuntu3.14
CVE-2026-59282026-07-272.35-0ubuntu3.14
CVE-2026-62382026-07-272.35-0ubuntu3.14
CVE-2025-152812026-01-202.35-0ubuntu3.13
CVE-2026-09152026-01-152.35-0ubuntu3.13
CVE-2026-08612026-01-142.35-0ubuntu3.13
CVE-2025-80582025-09-222.35-0ubuntu3.11
CVE-2025-48022025-05-282.35-0ubuntu3.10
CVE-2025-03952025-02-062.35-0ubuntu3.9
CVE-2024-335992024-05-312.35-0ubuntu3.8

Showing the 25 most recent of 34 that apply to Ubuntu 22.04 LTS, 6 of which have no fixed version released.

Ubuntu 24.04 LTSsource package: glibc

CVEPublishedFixed in package version
CVE-2026-868052026-09-22no fixed version released
CVE-2026-958182026-09-22no fixed version released
CVE-2026-86742026-09-17no fixed version released
CVE-2026-890922026-09-11no fixed version released
CVE-2026-194992026-09-102.39-0ubuntu8.9
CVE-2026-195422026-09-102.39-0ubuntu8.9
CVE-2026-63682026-09-102.39-0ubuntu8.9
CVE-2026-67912026-09-102.39-0ubuntu8.9
CVE-2026-771172026-09-102.39-0ubuntu8.9
CVE-2026-804892026-09-102.39-0ubuntu8.9
CVE-2026-183742026-08-27no fixed version released
CVE-2026-40462026-07-272.39-0ubuntu8.8
CVE-2026-44372026-07-272.39-0ubuntu8.8
CVE-2026-44382026-07-272.39-0ubuntu8.8
CVE-2026-54352026-07-272.39-0ubuntu8.8
CVE-2026-54502026-07-272.39-0ubuntu8.8
CVE-2026-59282026-07-272.39-0ubuntu8.8
CVE-2026-62382026-07-272.39-0ubuntu8.8
CVE-2025-152812026-01-202.39-0ubuntu8.7
CVE-2026-09152026-01-152.39-0ubuntu8.7
CVE-2026-08612026-01-142.39-0ubuntu8.7
CVE-2025-80582025-09-222.39-0ubuntu8.6
CVE-2025-57022025-07-142.39-0ubuntu8.5
CVE-2025-57452025-07-142.39-0ubuntu8.5
CVE-2025-03952025-02-062.39-0ubuntu8.4

Showing the 25 most recent of 35 that apply to Ubuntu 24.04 LTS, 6 of which have no fixed version released.

Debian 12 (bookworm)source package: glibc

CVEPublishedFixed in package version
CVE-2026-868052026-09-22no fixed version released
CVE-2026-958182026-09-22no fixed version released
CVE-2026-86742026-09-17no fixed version released
CVE-2026-771172026-09-15no fixed version released
CVE-2026-804892026-09-15no fixed version released
CVE-2026-194992026-09-14no fixed version released
CVE-2026-195422026-09-14no fixed version released
CVE-2026-890922026-09-11no fixed version released
CVE-2026-183742026-08-27no fixed version released
CVE-2026-63682026-08-10no fixed version released
CVE-2026-67912026-08-10no fixed version released
CVE-2026-54352026-04-28no fixed version released
CVE-2026-62382026-04-28no fixed version released
CVE-2026-54502026-04-20no fixed version released
CVE-2026-59282026-04-20no fixed version released
CVE-2026-40462026-03-302.36-9+deb12u14
CVE-2026-44372026-03-202.36-9+deb12u14
CVE-2026-44382026-03-202.36-9+deb12u14
CVE-2026-39042026-03-112.36-9
CVE-2025-152812026-01-202.36-9+deb12u14
CVE-2026-09152026-01-152.36-9+deb12u14
CVE-2026-08612026-01-142.36-9+deb12u14
CVE-2025-80582025-07-232.36-9+deb12u13
CVE-2025-48022025-05-162.36-9+deb12u11
CVE-2025-03952025-01-222.36-9+deb12u10

Showing the 25 most recent of 165 that apply to Debian 12 (bookworm), 22 of which have no fixed version released.

Debian 13 (trixie)source package: glibc

CVEPublishedFixed in package version
CVE-2026-868052026-09-22no fixed version released
CVE-2026-958182026-09-22no fixed version released
CVE-2026-86742026-09-17no fixed version released
CVE-2026-771172026-09-15no fixed version released
CVE-2026-804892026-09-15no fixed version released
CVE-2026-194992026-09-14no fixed version released
CVE-2026-195422026-09-14no fixed version released
CVE-2026-890922026-09-11no fixed version released
CVE-2026-183742026-08-27no fixed version released
CVE-2026-63682026-08-10no fixed version released
CVE-2026-67912026-08-10no fixed version released
CVE-2026-54352026-04-28no fixed version released
CVE-2026-62382026-04-28no fixed version released
CVE-2026-54502026-04-202.41-12+deb13u4
CVE-2026-59282026-04-202.41-12+deb13u4
CVE-2026-40462026-03-302.41-12+deb13u3
CVE-2026-44372026-03-202.41-12+deb13u3
CVE-2026-44382026-03-202.41-12+deb13u3
CVE-2026-39042026-03-112.36-9
CVE-2025-152812026-01-202.41-12+deb13u2
CVE-2026-09152026-01-152.41-12+deb13u2
CVE-2026-08612026-01-142.41-12+deb13u2
CVE-2025-80582025-07-232.41-11
CVE-2025-57022025-06-052.41-9
CVE-2025-57452025-06-052.41-9

Showing the 25 most recent of 168 that apply to Debian 13 (trixie), 20 of which have no fixed version released.

Rocky Linux 9source package: glibc

CVEPublishedFixed in package version
CVE-2026-54352026-07-230:2.34-274.el9_8
CVE-2026-59282026-07-230:2.34-274.el9_8
CVE-2026-62382026-07-230:2.34-274.el9_8
CVE-2026-54502026-07-010:2.34-272.el9_8
CVE-2026-40462026-05-300:2.34-270.el9_8
CVE-2026-44372026-05-300:2.34-270.el9_8
CVE-2026-44382026-05-300:2.34-270.el9_8
CVE-2025-152812026-02-240:2.34-231.el9_7.10
CVE-2026-08612026-02-240:2.34-231.el9_7.10
CVE-2026-09152026-02-240:2.34-231.el9_7.10
CVE-2025-80582025-10-040:2.34-168.el9_6.23
CVE-2025-48022025-10-040:2.34-168.el9_6.19
CVE-2025-57022025-10-040:2.34-168.el9_6.20
CVE-2025-03952025-07-290:2.34-125.el9_5.8
CVE-2024-29612024-06-140:2.34-100.el9_4.2
CVE-2024-335992024-06-140:2.34-100.el9_4.2
CVE-2024-336002024-06-140:2.34-100.el9_4.2
CVE-2024-336012024-06-140:2.34-100.el9_4.2
CVE-2024-336022024-06-140:2.34-100.el9_4.2

Showing the 19 most recent of 19 that apply to Rocky Linux 9.

AlmaLinux 9source package: glibc

CVEPublishedFixed in package version
CVE-2026-54352026-07-212.34-274.el9_8
CVE-2026-59282026-07-212.34-274.el9_8
CVE-2026-62382026-07-212.34-274.el9_8
CVE-2026-54502026-06-292.34-272.el9_8
CVE-2026-40462026-05-262.34-270.el9_8
CVE-2026-44372026-05-262.34-270.el9_8
CVE-2026-44382026-05-262.34-270.el9_8
CVE-2025-152812026-02-172.34-231.el9_7.10
CVE-2026-08612026-02-172.34-231.el9_7.10
CVE-2026-09152026-02-172.34-231.el9_7.10
CVE-2025-57022025-06-302.34-168.el9_6.20
CVE-2025-48022025-06-092.34-168.el9_6.19
CVE-2025-03952025-04-282.34-125.el9_5.8.alma.1
CVE-2024-29612024-05-232.34-100.el9_4.2
CVE-2024-335992024-05-232.34-100.el9_4.2
CVE-2024-336002024-05-232.34-100.el9_4.2
CVE-2024-336012024-05-232.34-100.el9_4.2
CVE-2024-336022024-05-232.34-100.el9_4.2
CVE-2023-45272023-10-052.34-60.el9_2.7
CVE-2023-48062023-10-052.34-60.el9_2.7
CVE-2023-48132023-10-052.34-60.el9_2.7
CVE-2023-49112023-10-052.34-60.el9_2.7

Showing the 22 most recent of 22 that apply to AlmaLinux 9.

Advisory data last refreshed 26 September 2026. It is re-read daily.

What this page does not tell you

It does not tell you whether your server is affected. A CVE applying to a package is not the same as a CVE applying to your installation: the fix may already be backported into what you are running, the vulnerable module may not be loaded, or the service may not be reachable from anywhere that matters. Answering that needs the versions on your machine, not a list.

It also carries no count of how many servers are affected. SecAI monitors a small fleet, and a percentage drawn from it would be arithmetic on a sample too small to mean anything. When that changes, the number will appear here and the page will say when it started.

Read next

Find out which of these you are running

One read-only command, no account, no agent. It reads the installed package versions on your server and tells you which advisories actually apply to them, GNU C Library included. It changes nothing.