๐Ÿ” CVE Alert

CVE-2026-5435

UNKNOWN 0.0

Potential buffer overflow in ns_sprintrrf TSIG handling path

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

CWE CWE-787
Vendor the gnu c library
Product glibc
Published Apr 28, 2026
Stay Ahead of the Next One

Get instant alerts for the gnu c library glibc

Be the first to know when new unknown vulnerabilities affecting the gnu c library glibc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The GNU C Library / glibc
2.2 โ‰ค *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
sourceware.org: https://sourceware.org/bugzilla/show_bug.cgi?id=34033 inbox.sourceware.org: https://inbox.sourceware.org/libc-announce/[email protected]/T/#u

Credits

shinobu