Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-28372

Опубликовано: 27 фев. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

РелизСтатусПримечание
devel

not-affected

2:2.8-2ubuntu1
esm-apps-legacy/xenial

released

2:1.9.4-1ubuntu0.1~esm6
esm-apps/bionic

released

2:1.9.4-3ubuntu0.1+esm5
esm-apps/focal

released

2:1.9.4-11ubuntu0.2+esm4
esm-apps/jammy

released

2:2.2-2ubuntu0.2+esm1
esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

released

2:1.9.2-1ubuntu0.1~esm4
jammy

needed

noble

released

2:2.5-3ubuntu4.2
questing

released

2:2.6-1ubuntu3.2

Показывать по

EPSS

Процентиль: 30%
0.00373
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
6 месяцев назад

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

CVSS3: 7.4
debian
6 месяцев назад

telnetd in GNU inetutils through 2.7 allows privilege escalation that ...

CVSS3: 7.4
github
6 месяцев назад

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

CVSS3: 7.4
fstec
6 месяцев назад

Уязвимость сервера telnetd пакета сетевых программ inetutils, позволяющая нарушителю повысить свои привилегии до уровня root

EPSS

Процентиль: 30%
0.00373
Низкий

7.4 High

CVSS3