FAIL › dossier
gnu
VENDOR· dossier confidence 50%
GNU, a foundational software organization, exhibits a concerning pattern of high-severity vulnerabilities, particularly remote code execution flaws, across its core components. This history raises significant security concerns for organizations relying on GNU software.
PROFILE
CategorySoftware FoundationWhat they doThe GNU Project develops and maintains free software, including the GNU operating system and numerous utilities. It is a collaborative project involving numerous developers worldwide.
SECURITY POSTURE
GNU has a history of high-severity remote code execution (RCE) vulnerabilities across multiple core components, indicating a potential weakness in secure coding practices and vulnerability management. The repeated occurrence of these vulnerabilities suggests systemic issues.
Notable failures
- CVE-2026-24061 (RCE)
- CVE-2014-6278 (RCE)
- CVE-2014-6271 (RCE)
- CVE-2023-4911 (Code Execution)
- CVE-2026-42010 (Authentication Bypass)
- CVE-2026-33845 (Out-of-bounds Write)
Patterns: Repeated RCE vulnerabilities; Vulnerabilities in core utilities (Bash, InetUtils, C Library); Integer underflow vulnerabilities; Authentication bypass vulnerabilities
FAILURE HISTORY · 7
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-01-28 | CVE-2014-6271 | high | A remote code execution flaw in GNU Bash allowed attackers to execute arbitrary code via environment variables in versions 4.3 and earlier. |
| 2022-01-28 | CVE-2014-7169 | high | A remote code execution flaw in GNU Bash allowed attackers to execute arbitrary code via environment variables, a known vulnerability that remains actively exploited in the wild. |
| 2026-01-26 | CVE-2026-24061 | high | GNU InetUtils telnetd exposed to remote authentication bypass |
| 2025-10-02 | CVE-2014-6278 | high | GNU Bash OS command injection allowed remote code execution |
| 2023-11-21 | CVE-2023-4911 | high | Local attacker can execute code with elevated privileges due to buffer overflow in GNU C Library. |
| 2026-05-07 | CVE-2026-42010 | high | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe |
| 2026-04-30 | CVE-2026-33845 | high | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of |
Open questions: What is GNU's vulnerability disclosure process? · What are GNU's internal security testing and code review practices? · What is the extent of GNU's reliance on external contributions and how are those contributions vetted?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-22 04:25:04.935640+00:00