CVE 7.3 HIGH

Potential buffer overflow in ns_sprintrrf TSIG handling path_CVE-2026-5435

7.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Description

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Basic Information

ID CVE-2026-5435
Source glibc
Published Apr 28, 2026 at 11:58
Modified Apr 28, 2026 at 15:21

Affected Product

Vendor The GNU C Library
Product glibc
Version 2.2
Affected Versions The GNU C Library glibc 2.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.