CVE-2026-5435

Published: April 29, 2026Last modified: July 10, 2026

Description

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Severity score breakdown

ParameterValue
Base score7.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactLOW
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSglibcFixed (2.37.0-r24)
25 LTSglibcFixed (2.39.0-r9)
StreamglibcFixed (2.43.0-r1)
Hardened Containers23 LTSglibcFixed (2.37.0-r24)
25 LTSglibcFixed (2.39.0-r9)
StreamglibcFixed (2.43.0-r1)

References

ON THIS PAGE