« List of all CVEs

CVE-2026-5435

Potential buffer overflow in ns_sprintrrf TSIG handling path

Published: 4/28/2026 Last updated: 4/28/2026 Reserved: 4/2/2026

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

CNA assigner: glibc (3ff69d7a-14f2-4f67-a097-88dee7810d18) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.3 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Opam packages affected (1)

gettext-stub

Products affected (1)

Product Vendor Version
glibc The GNU C Library P9,Honor 6 Versions before EVA-AL10C00B192,Versions before H60-L02_6.10.1

References (2)

Credits (1)