Skip to content
COOEY

FAIL › dossier

gnu

VENDOR

· dossier confidence 50%

GNU, a foundational software organization, exhibits a concerning pattern of high-severity vulnerabilities, particularly remote code execution flaws, across its core components. This history raises significant security concerns for organizations relying on GNU software.

PROFILE
CategorySoftware FoundationWhat they doThe GNU Project develops and maintains free software, including the GNU operating system and numerous utilities. It is a collaborative project involving numerous developers worldwide.
SECURITY POSTURE

GNU has a history of high-severity remote code execution (RCE) vulnerabilities across multiple core components, indicating a potential weakness in secure coding practices and vulnerability management. The repeated occurrence of these vulnerabilities suggests systemic issues.

Notable failures
  • CVE-2026-24061 (RCE)
  • CVE-2014-6278 (RCE)
  • CVE-2014-6271 (RCE)
  • CVE-2023-4911 (Code Execution)
  • CVE-2026-42010 (Authentication Bypass)
  • CVE-2026-33845 (Out-of-bounds Write)
Patterns: Repeated RCE vulnerabilities; Vulnerabilities in core utilities (Bash, InetUtils, C Library); Integer underflow vulnerabilities; Authentication bypass vulnerabilities
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2022-01-28 CVE-2014-6271 high A remote code execution flaw in GNU Bash allowed attackers to execute arbitrary code via environment variables in versions 4.3 and earlier.
2022-01-28 CVE-2014-7169 high A remote code execution flaw in GNU Bash allowed attackers to execute arbitrary code via environment variables, a known vulnerability that remains actively exploited in the wild.
2026-01-26 CVE-2026-24061 high GNU InetUtils telnetd exposed to remote authentication bypass
2025-10-02 CVE-2014-6278 high GNU Bash OS command injection allowed remote code execution
2023-11-21 CVE-2023-4911 high Local attacker can execute code with elevated privileges due to buffer overflow in GNU C Library.
2026-05-07 CVE-2026-42010 high A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authe
2026-04-30 CVE-2026-33845 high A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of
Open questions: What is GNU's vulnerability disclosure process? · What are GNU's internal security testing and code review practices? · What is the extent of GNU's reliance on external contributions and how are those contributions vetted?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-22 04:25:04.935640+00:00