NIXPKGS-2026-0660
GitHub issue
published on 16 Mar 2026
Permalink
CVE-2026-32746
9.8 CRITICAL
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write …
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
References
Affected products
inetutils
- =<2.7
Package maintainers
-
@matthewbauer Matthew Bauer <mjbauer95@gmail.com>