<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_homebrew</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:34:16 +0000</lastBuildDate>
    <item>
      <title>BREW-glibc-CVE-2024-2961</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-2961</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-2961</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2024-33599 — nscd: Stack-based buffer overflow in netgroup cache</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-33599</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;nscd: Stack-based buffer overflow in netgroup cache&lt;/p&gt;
&lt;p&gt;If the Name Service Cache Daemon&amp;#39;s (nscd) fixed size cache is exhausted
by client requests then a subsequent client request for netgroup data
may result in a stack-based buffer overflow.  This flaw was introduced
in glibc 2.15 when the cache was added to nscd.&lt;/p&gt;
&lt;p&gt;This vulnerability is only present in the nscd binary.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;nscd: Stack-based buffer overflow in netgroup cache&lt;/p&gt;
&lt;p&gt;If the Name Service Cache Daemon&amp;#39;s (nscd) fixed size cache is exhausted
by client requests then a subsequent client request for netgroup data
may result in a stack-based buffer overflow.  This flaw was introduced
in glibc 2.15 when the cache was added to nscd.&lt;/p&gt;
&lt;p&gt;This vulnerability is only present in the nscd binary.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-33599</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2024-33600 — nscd: Null pointer crashes after notfound response</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-33600</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;nscd: Null pointer crashes after notfound response&lt;/p&gt;
&lt;p&gt;If the Name Service Cache Daemon&amp;#39;s (nscd) cache fails to add a not-found
netgroup response to the cache, the client request can result in a null
pointer dereference.  This flaw was introduced in glibc 2.15 when the
cache was added to nscd.&lt;/p&gt;
&lt;p&gt;This vulnerability is only present in the nscd binary.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;nscd: Null pointer crashes after notfound response&lt;/p&gt;
&lt;p&gt;If the Name Service Cache Daemon&amp;#39;s (nscd) cache fails to add a not-found
netgroup response to the cache, the client request can result in a null
pointer dereference.  This flaw was introduced in glibc 2.15 when the
cache was added to nscd.&lt;/p&gt;
&lt;p&gt;This vulnerability is only present in the nscd binary.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-33600</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2024-33601 — nscd: netgroup cache may terminate daemon on memory allocation failure</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-33601</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;nscd: netgroup cache may terminate daemon on memory allocation failure&lt;/p&gt;
&lt;p&gt;The Name Service Cache Daemon&amp;#39;s (nscd) netgroup cache uses xmalloc or
xrealloc and these functions may terminate the process due to a memory
allocation failure resulting in a denial of service to the clients.  The
flaw was introduced in glibc 2.15 when the cache was added to nscd.&lt;/p&gt;
&lt;p&gt;This vulnerability is only present in the nscd binary.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;nscd: netgroup cache may terminate daemon on memory allocation failure&lt;/p&gt;
&lt;p&gt;The Name Service Cache Daemon&amp;#39;s (nscd) netgroup cache uses xmalloc or
xrealloc and these functions may terminate the process due to a memory
allocation failure resulting in a denial of service to the clients.  The
flaw was introduced in glibc 2.15 when the cache was added to nscd.&lt;/p&gt;
&lt;p&gt;This vulnerability is only present in the nscd binary.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2024-33601</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2025-0395</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-0395</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-0395</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2025-15281 — wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-15281</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-15281</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2025-5702</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-5702</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the caller, or leaking the input strings to the function to other parts of the program.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-5702</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2025-8058</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-8058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;The regcomp function in the GNU C library version from 2.4 to 2.41 is 
subject to a double free if some previous allocation fails. It can be 
accomplished either by a malloc failure or by using an interposed malloc
 that injects random malloc failures. The double free can allow buffer 
manipulation depending of how the regex is constructed. This issue 
affects all architectures and ABIs supported by the GNU C library.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;The regcomp function in the GNU C library version from 2.4 to 2.41 is 
subject to a double free if some previous allocation fails. It can be 
accomplished either by a malloc failure or by using an interposed malloc
 that injects random malloc failures. The double free can allow buffer 
manipulation depending of how the regex is constructed. This issue 
affects all architectures and ABIs supported by the GNU C library.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2025-8058</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2026-0861 — Integer overflow in memalign leads to heap corruption</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0861</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0861</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
    <item>
      <title>BREW-glibc-CVE-2026-0915 — getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0915</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library&amp;#39;s DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library&amp;#39;s DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0915</guid>
      <pubDate>Sun, 28 Jun 2026 21:29:54 +0000</pubDate>
    </item>
  </channel>
</rss>
