CVE-2026-5358
Static buffer overflow in deprecated nis_local_principal
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof a crafted response to a UDP request generated by this function and overwrite neighboring static data in the requesting application. NIS support is obsolete and has been deprecated in the GNU C Library since version 2.26 and is only maintained for legacy usage. Applications should port away from NIS to more modern identity and access management services.
| CWE | CWE-120 |
| Vendor | the gnu c library |
| Product | glibc |
| Published | Apr 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for the gnu c library glibc
Be the first to know when new unknown vulnerabilities affecting the gnu c library glibc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
The GNU C Library / glibc
0 โค 2.43
References
Credits
Rahul Hoysala