Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5435

Опубликовано: 28 апр. 2026
Источник: redhat
CVSS3: 5.9

Описание

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-glibcFix deferred
Red Hat Enterprise Linux 6glibcFix deferred
Red Hat Enterprise Linux 7compat-glibcFix deferred
Red Hat Enterprise Linux 7glibcFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat Enterprise Linux 10glibcFixedRHSA-2026:4269421.07.2026
Red Hat Enterprise Linux 8glibcFixedRHSA-2026:4273321.07.2026
Red Hat Enterprise Linux 8glibcFixedRHSA-2026:4273321.07.2026
Red Hat Enterprise Linux 9glibcFixedRHSA-2026:4295222.07.2026
Red Hat Enterprise Linux 9glibcFixedRHSA-2026:4295222.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2463465glibc: glibc: Out-of-bounds write via TSIG record processing

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

CVSS3: 7.3
nvd
3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

msrc
3 месяца назад

Potential buffer overflow in ns_sprintrrf TSIG handling path

CVSS3: 7.3
debian
3 месяца назад

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the ...

CVSS3: 7.3
redos
23 дня назад

Уязвимость glibc

5.9 Medium

CVSS3