Morty[verified]@MortyJinDisclosure
Justin Swartz disclosed that GCONV_PATH injection in GNU Inetutils telnetd remains exploitable, enabling arbitrary root code execution, despite the earlier patch for CVE‑2026‑24061.
NanoVMs@nanovmsPatch
The post announces a new CVE and offers mitigations such as banning users and shells or using unikernels, but provides no PoC, exploit code, or technical details about the vulnerability.
Open Source Security mailing list@oss_securityPoC
The post reports that CVE-1999-0073 still has an incomplete fix and that new local privilege escalation PoCs using CREDENTIALS_DIRECTORY and GCONV_PATH have been discovered.
iototsecnews@iototsecnewsDisclosure
The article announces that CVE‑2026‑24061, a 27‑year‑old vulnerability in GNU Inetutils telnetd, has resurfaced, permitting unauthenticated remote users to obtain root access via unsanitized environment variables.