Given CVE-2023-4911: https://security-tracker.debian.org/tracker/CVE-2023-4911 There is no link between glibc and this CVE in data from debsecan security tracker( https://security-tracker.debian.org/tracker/debsecan/release/1/GENERIC), therefore debsecan doesn't report this CVE on any debian and we can't rely on it.