CVE-2026-24061Active Exploitation(debian / debian_linux)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-88

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • inetutils

Threat summary

  • Active exploitation appears in 33 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 123 mentions across 52 observed days

What's happening

  • Active exploitation reported across 33 signals
  • Exploit tool or code specified in 19 signals
  • PoC mentioned or linked in 24 signals
  • Patch or workaround mentioned in 42 signals
  • Technical details provided in 73 signals
  • Disclosure: 26 classified signals
  • General: 24 classified signals
  • Peaked 50d ago at 10 mentions (2026-01-28); latest day: 2
  • 123 total mentions across 52 days

Affected systems

Vendors
Products
debian_linuxinetutils

1 version affected across 2 products

Deep dive

Activity timeline123 mentions / 52d
035810Mentions · 2026-01-27: 7Mentions · 2026-01-28: 10Mentions · 2026-01-29: 10Mentions · 2026-01-30: 9Mentions · 2026-01-31: 7Mentions · 2026-02-01: 2Mentions · 2026-02-02: 4Mentions · 2026-02-03: 4Mentions · 2026-02-04: 4Mentions · 2026-02-05: 5Mentions · 2026-02-06: 3Mentions · 2026-02-07: 1Mentions · 2026-02-08: 1Mentions · 2026-02-09: 2Mentions · 2026-02-10: 2Mentions · 2026-02-11: 3Mentions · 2026-02-12: 1Mentions · 2026-02-14: 4Mentions · 2026-02-15: 4Mentions · 2026-02-16: 1Mentions · 2026-02-19: 1Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 2Mentions · 2026-03-01: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Mentions · 2026-03-20: 2Mentions · 2026-03-27: 1Mentions · 2026-04-07: 2Mentions · 2026-04-09: 1Mentions · 2026-05-08: 2Mentions · 2026-05-11: 1Mentions · 2026-07-02: 1Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Mentions · 2026-07-10: 1Mentions · 2026-07-12: 1Mentions · 2026-07-14: 1Mentions · 2026-08-03: 1Mentions · 2026-08-10: 1Mentions · 2026-08-15: 1Mentions · 2026-08-17: 1Mentions · 2026-08-18: 1Mentions · 2026-08-23: 1Mentions · 2026-09-12: 1Mentions · 2026-09-15: 1Mentions · 2026-09-25: 1Mentions · 2026-10-09: 2PoC Mentioned / Linked · 2026-01-28: 3PoC Mentioned / Linked · 2026-01-29: 2PoC Mentioned / Linked · 2026-01-30: 2PoC Mentioned / Linked · 2026-01-31: 1PoC Mentioned / Linked · 2026-02-02: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-01: 1PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-08-15: 1PoC Mentioned / Linked · 2026-08-18: 1PoC Mentioned / Linked · 2026-08-23: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-01-28: 4Exploit Tool / Code · 2026-01-29: 2Exploit Tool / Code · 2026-01-30: 2Exploit Tool / Code · 2026-01-31: 1Exploit Tool / Code · 2026-02-04: 1Exploit Tool / Code · 2026-02-25: 1Exploit Tool / Code · 2026-02-28: 1Exploit Tool / Code · 2026-04-09: 1Exploit Tool / Code · 2026-05-11: 1Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-07-14: 1Exploit Tool / Code · 2026-08-15: 1Exploit Tool / Code · 2026-08-17: 1Exploit Tool / Code · 2026-08-18: 1Active Exploitation · 2026-01-27: 3Active Exploitation · 2026-01-28: 4Active Exploitation · 2026-01-29: 3Active Exploitation · 2026-01-31: 1Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-02-03: 1Active Exploitation · 2026-02-04: 2Active Exploitation · 2026-02-05: 1Active Exploitation · 2026-02-14: 4Active Exploitation · 2026-02-15: 4Active Exploitation · 2026-02-16: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-03-06: 1Active Exploitation · 2026-05-08: 2Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-09-15: 1Patch / Workaround · 2026-01-27: 2Patch / Workaround · 2026-01-28: 4Patch / Workaround · 2026-01-29: 2Patch / Workaround · 2026-01-30: 4Patch / Workaround · 2026-01-31: 4Patch / Workaround · 2026-02-01: 1Patch / Workaround · 2026-02-02: 2Patch / Workaround · 2026-02-03: 3Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-05: 3Patch / Workaround · 2026-02-07: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-14: 2Patch / Workaround · 2026-02-15: 3Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-05-08: 1Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-15: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-01-27: 4Technical Details · 2026-01-28: 8Technical Details · 2026-01-29: 5Technical Details · 2026-01-30: 6Technical Details · 2026-01-31: 3Technical Details · 2026-02-01: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-03: 4Technical Details · 2026-02-04: 3Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 3Technical Details · 2026-02-07: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-14: 3Technical Details · 2026-02-15: 3Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-01: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-09: 1Technical Details · 2026-05-11: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-14: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-23: 1Technical Details · 2026-09-25: 101-2702-0102-0602-1102-1902-2803-2005-1107-1208-1709-2510-09
Signal classification6 categories
Active Exploitation
3327.3%
Disclosure
2621.5%
General
2419.8%
Patch
1613.2%
PoC
1512.4%
Exploit
75.8%
Referenced assets98 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-277
Active Exploitation3Disclosure1Exploit1General1Patch1
2026-01-2810
Active Exploitation4Disclosure1Exploit1General1Patch2PoC1
2026-01-2910
Active Exploitation3Disclosure2Exploit1General3PoC1
2026-01-309
Disclosure4General1Patch2PoC2
2026-01-317
Active Exploitation1Exploit1General3Patch2
2026-02-012
General1Patch1
2026-02-024
Active Exploitation1Disclosure1Patch1PoC1
2026-02-034
Active Exploitation1Disclosure1General1Patch1
2026-02-044
Active Exploitation2Disclosure1Exploit1
2026-02-055
Active Exploitation1General1Patch3
2026-02-063
Disclosure3
2026-02-071
Patch1
2026-02-081
Disclosure1
2026-02-092
Disclosure1General1
2026-02-102
General1PoC1
2026-02-113
Disclosure1General2
2026-02-121
General1
2026-02-144
Active Exploitation4
2026-02-154
Active Exploitation4
2026-02-161
Active Exploitation1
2026-02-191
General1
2026-02-241
Disclosure1
2026-02-251
Active Exploitation1
2026-02-262
Disclosure1General1
2026-02-271
Disclosure1
2026-02-282
Disclosure1Exploit1
2026-03-012
General1PoC1
2026-03-051
Disclosure1
2026-03-061
Active Exploitation1
2026-03-081
PoC1
2026-03-202
Disclosure1General1
2026-03-271
General1
2026-04-072
General1PoC1
2026-04-091
PoC1
2026-05-082
Active Exploitation2
2026-05-111
PoC1
2026-07-021
Patch1
2026-07-071
PoC1
2026-07-081
PoC1
2026-07-101
PoC1
2026-07-121
PoC1
2026-07-141
Active Exploitation1
2026-08-031
Patch1
2026-08-101
Disclosure1
2026-08-151
Active Exploitation1
2026-08-171
Active Exploitation1
2026-08-181
Exploit1
2026-08-231
General1
2026-09-121
Disclosure1
2026-09-151
Active Exploitation1
2026-09-251
Disclosure1
Full discourse20 posts
  • OffSec@offsectraining
    Patch

    🚨 CVE-2026-24061 - Critical Alert 🚨 A critical (CVSS 9.8) vulnerability in GNU InetUtils telnetd lets unauthenticated attackers bypass login and gain root access on affected systems. With an EPSS score ~92%, exploitation risk is extremely high. 📌 What to do: - Patch to the latest GNU InetUtils immediately - Disable Telnet where possible 👉 Full breakdown here: https://www.offsec.com/blog/cve-2026-24061/

    Post summary

    CVE-2026-24061 is a high‑severity flaw in GNU InetUtils telnetd that allows unauthenticated attackers to bypass login and gain root access; patch immediately or disable Telnet.

    5111244417130.2K
    327.1K followersView on X
  • ASH@ashy0x41
    General

    Telnetの深刻な脆弱性(CVE-2026-24061)が公表される6日前にTelnet通信の大幅な減少が観測されていたという話とその考察。 いくつかの特定ASでフィルターが入った可能性が示唆されるとのこと。興味深い。

    Post summary

    The post observes a drop in Telnet traffic six days before CVE-2026-24061 was disclosed and speculates that filters may have been applied by certain AS, but it offers no technical detail, PoC, or evidence of exploitation.

    210623189244.3K
    858 followersView on X
  • 👑 OFJAAAH 👑@ofjaaah
    PoC

    🔥Full CVE-2026-24061 Recon Pipeline - Oneliners🔥 https://github.com/KingOfBugbounty/KingOfBugBountyTips #CVE202624061 #criticalCVE https://t.co/hpoWIzjnU7

    Post summary

    The tweet shares a GitHub repository offering a full one-line recon pipeline for CVE-2026-24061, indicating that a proof‑of‑concept or exploit code is available.

    041022115111.8K
    19.8K followersView on X
  • Germán Fernández@1ZRR4H
    General

    🔸 45[.]137[.]70[.]27:8080 #opendir 🔎 → CVE-2026-24061 (Telnetd Auth Bypass) → CVE-2024-3721 (TBK DVR Command Injection) → CVE-2024-10443 (Synology RCE via Crontab) https://t.co/ybGabCZnj3

    Post summary

    The tweet lists three CVEs with brief vulnerability descriptors and a link, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    020095638.4K
    37.6K followersView on X
  • coffnix@coffnix
    Active Exploitation

    Linux sendo Linux. CVE crítico no telnetd do GNU inetutils dando root remoto sem autenticação (CVE-2026-24061) bug esse introduzido em 2015 e que ficou quase 10 anosativo no código. Nível? CVSS 9.8, exploração trivial, zero credencial, zero interação, basta mandar USER como “-f root” e o login aceita feliz da vida. Exploração ativa fácil e rodando em 99% dos servidores e desktops Linux. E ainda tem gente rodando telnet em produção em 2026 ou defendendo o Linux no desktop falando que é mais "seguro" hein kkkkkk. Depois me perguntam pq considero o Linux inseguro PRA CARALHO né. Isso é mais um dos inúmeros lixos legados que quase todo Linux carrega. Serviço antiquado mantido por "compatibilidade" (eles disseram...), na prática é código remendado e ninguém responsável de verdade pela segurança cibernética. A resposta padrão pra esse tipo de falha tosca é sempre a mesma, aplica patch 10 anos quase depois, fecha porta e finge que o bug nunca existiu, como se isso fosse normal. E vai ter idiota normalizando uma falha de segurança ativa a quase 10 anos hein. kkkkkkkkk UNIX de verdade como o XNU/darwin da Apple e BSDs já tratam telnet como peça de museu a decadas. OpenBSD e FreeBSD sempre foram paranóicos com segurança, design limpo, isolamento completo e menos superfície de ataque. No macOS isso nem existe. Em suma, Linux em cybersec é gambiarra empilhada, BSDs e XNU/darwin seguem outra linha que é o que chamamos de security by design. E outro ponto, nunca vi a apple demorar mais de 60 dias pra corrigir uma falha de segurança. fonte: https://nvd.nist.gov/vuln/detail/CVE-2026-24061

    Post summary

    The post reports that CVE‑2026‑24061 is actively exploited on nearly all Linux systems, provides exploitation details, and calls for patching while criticizing the delayed response.

    215667337.8K
    6.5K followersView on X
  • X@SansLimit3
    Active Exploitation

    Exposed attacker infra scanning #CVE-2026-24061 using custom exploits. Bash history and directory artifacts reveal #KrakenNet #DoS tool deployment and external payload downloads. 176[.]65.148.254:8080 212[.]135.38.87 94[.]26.106.137 @malwrhunterteam @UK_Daniel_Card @1ZRR4H https://t.co/Urel0cp9IB

    Post summary

    The tweet claims attacker infrastructure is actively scanning and exploiting CVE-2026-24061 with custom exploits, referencing a DoS tool, but provides no PoC, patch, or technical details.

    212072455.3K
    205 followersView on X
  • SoyITPro@SoyITPro
    Disclosure

    🚨 Nueva vulnerabilidad crítica: CVE-2026-24061 #Linux El servicio GNU InetUtils telnetd permite acceso root sin credenciales por un fallo en la validación de USER. https://orca.security/resources/blog/cve-2026-24061-gnu-inetutils-telnetd-bypass/ https://t.co/6CrVXLVUlG

    Post summary

    A new critical vulnerability (CVE-2026-24061) in GNU InetUtils telnetd allows attackers to gain root access without credentials through a USER validation flaw. The announcement includes a link to a blog but no exploit code or patch information.

    023062223.5K
    12.1K followersView on X
  • LCFR@lcfr_eth
    Disclosure

    Pwnies this year a joke or something (who am i kidding every year?) Best RCE: Winner: ITScape: Guest-to-Host escape in KVM/arm64 (CVE-2026-46316) <- a bug which requires a shell/foothold on a target? (awesome bug. but ..) Remote authentication bypass in the GNU InetUtils telnetd (CVE-2026-24061) <- a daemon not in use anywhere. SELECT shell FROM postgres (CVE-2026-2006) <- probably never going to be exploited ITW. but not the preauth wordpress rce by @assetnote ...?

    Post summary

    The tweet announces several new RCE CVEs from the Pwnies 2026 event, listing their basic properties but providing no PoC, exploit code, patches, or evidence of active attacks.

    27044135.4K
    2.8K followersView on X
  • Censys@censysio
    Active Exploitation

    🚨 CVE-2026-24061: Critical (CVSS 9.8) remote authentication bypass vulnerability in GNU Inetutils telnetd allows unauthenticated attackers to gain root-level access to affected systems. Successful exploitation results in RCE with full system privileges. 🔴 CVSS 9.8 ⚠️ Actively exploited in the wild 🛠️ Affects GNU Inetutils telnetd version 1.9.3 up to and including version 2.7 ✔️ A patch has been merged upstream in GNU Inetutils 2.8. Upgrade immediately to a patched version or disable telnetd entirely, especially if exposed to the internet. 🔗 Full advisory: https://hubs.ly/Q040J7nG0 #CVE202624061 #infosec

    Post summary

    CVE-2026-24061 is a critical remote authentication bypass in GNU Inetutils telnetd that attackers are actively exploiting for root-level RCE; a patch is available in version 2.8 and urgent upgrade or disabling is advised.

    1613682.7K
    11.9K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    New video is live! 🚀 CraftCMS RCE to Root via Telnetd Auth Bypass In this walkthrough, we exploit CraftCMS CVE-2025-32432 for RCE, discover MySQL credentials, abuse password reuse for SSH access, and escalate to root via Telnetd CVE-2026-24061. https://youtu.be/eS7OLz_2FQo

    Post summary

    The tweet announces a video walkthrough that demonstrates the exploitation of CraftCMS CVE-2025-32432 to achieve remote code execution and root access via Telnetd CVE-2026-24061.

    0512695.1K
    12.3K followersView on X
  • NtAlertThread@ElementalX2
    Active Exploitation

    Recovered a very weird open directory located out of China, using @etugenio , possibly related to anti-corruption bureau(?) , while contrasting they are abusing instances related to CVE-2026-24061 PoC written @C2IRIS , bonus, found this weird video as well, possible AI-Generated, related to anti-corruption!

    Post summary

    The post claims instances related to CVE-2026-24061 are being abused and mentions a PoC written by @C2IRIS. While it also references a PoC, the strongest indicator is the report of active abuse.

    1501251.1K
    2.4K followersView on X
  • NullSecurityX@NullSecurityX
    PoC

    CraftCMS RCE to Root via Telnetd Auth Bypass We exploit CraftCMS CVE-2025-32432 for RCE, discover MySQL credentials, abuse password reuse for SSH access, and escalate to root via Telnetd CVE-2026-24061. https://youtu.be/eS7OLz_2FQo

    Post summary

    The post demonstrates a multi‑step exploitation chain against CraftCMS and Telnetd, providing technical details but lacking explicit code, tools, or patch information.

    0101432.2K
    12.3K followersView on X
  • Justin Elze@HackingLZ
    PoC

    CVE-2026-32746 (GNU inetutils telnetd) - 32 years https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/ CVE-2026-24061 (GNU inetutils telnetd) - 11 years https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/

    Post summary

    The excerpt references two CVEs in GNU inetutils telnetd, providing a link to a PoC exploit for CVE‑2026‑24061, while also describing technical details of the vulnerabilities but without mentioning active exploitation, patches, or false‑positive claims.

    030961.9K
    70.8K followersView on X
  • 竹林人間🍣🍊3g+◢@Chromium_Linux
    PoC

    CVE-2026-24061、簡単にパスワードなしでログインできるのやばwww https://t.co/twhADJgLBD

    Post summary

    The tweet announces CVE-2026-24061, claims it allows login without a password, and provides a link that likely contains a proof‑of‑concept.

    10094919
    8.5K followersView on X
  • BINARLY🔬@binarly_io
    PoC

    ...and, finally, a rule for the very recent authentication bypass in telnetd (CVE-2026-24061). Test case(s): https://github.com/vulhunt-re/tests/tree/main/posix/CVE-2026-24061 Rule: https://github.com/vulhunt-re/rules/blob/main/posix/CVE-2026-24061.vh https://t.co/hHsioMt6x0

    Post summary

    The tweet supplies test cases and a rule file for CVE‑2026‑24061, indicating a proof‑of‑concept exists, but provides no exploit code, patch, or details of active exploitation.

    03092521
    4.3K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    2026 ولازلنا نناقش مصايب Telnet والبروتوكولات القديمة! ثغرة حرجة (CVE-2026-24061) في GNU InetUtils تعطي المهاجم صلاحيات Root بـ "سطر واحد" ، وبدون باسوورد حتى. الـ الاستغلال سهل والهجمات بدأت فعلياً من قبل المخترقين. [1/3] https://t.co/tIvrqemXuB

    Post summary

    CVE-2026-24061 in GNU InetUtils permits attackers to gain root privileges with a single line and no password, and reports indicate that exploitation has already begun in the wild.

    10084965
    46.9K followersView on X
  • loudog@loudoggeek
    Patch

    Critical patch for CVE-2026-24061 on Synology is out. Patch now, and patch any other system using telnetd. Also, it's 2026 so freaking set up SSH and disable TELNET, k? @ITSPARCCast

    Post summary

    A critical patch for CVE-2026-24061 on Synology has been released, and users are advised to apply it and disable TELNET. No exploitation details or PoC are mentioned.

    02070226
    569 followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    General

    Exploit Lab: CVE-2026–24061 (telnetd) https://medium.com/@josh.beck2006/exploit-lab-cve-2026-24061-telnetd-772306d3b0ba?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The text references a telnetd vulnerability (CVE-2026‑24061) but offers no concrete evidence of a PoC, exploit code, active exploitation, or patch information.

    00054813
    40.2K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    General

    How CVE-2026–24061 Grants Instant Root via Telnet https://medium.com/@mhammadalkhateeb22/how-cve-2026-24061-grants-instant-root-via-telnet-ad49019572e6?source=rss------bug_bounty-5 #bugbounty #bugbountytips #bugbountytip

    Post summary

    The post only references CVE-2026-24061 and hints at root privilege via Telnet, but offers no PoC, exploitation details, patch info, or technical depth.

    01042817
    40.2K followersView on X
  • Morty@MortyJin
    Disclosure

    GCONV_PATH Injection in GNU Inetutils telnetd Credit: Discovered by Justin Swartz Reference: https://seclists.org/oss-sec/2026/q1/199 Justin revealed that while CVE-2026-24061 fix addressed the "-f root" authentication bypass, the underlying environment variable sanitization issue remains incomplete. Technical Details: ▪️ telnetd's scrub_env() blacklist misses GCONV_PATH, LANGUAGE, OUTPUT_CHARSET ▪️ When telnetd (running as root) execs /bin/login, AT_SECURE=0 ▪️ glibc doesn't sanitize these dangerous variables ▪️ gettext triggers iconv_open() → loads malicious .so via GCONV_PATH ▪️ Result: Arbitrary code execution as root Timeline: 1999: CVE-1999-0073 disclosed 2026: CVE-2026-24061 patched (USER variable injection) 2026-Feb: Justin Swartz discloses GCONV_PATH vector still exploitable #Security #Infosec #CVE #Linux #Telnetd #PrivilegeEscalation

    Post summary

    Justin Swartz disclosed that GCONV_PATH injection in GNU Inetutils telnetd remains exploitable, allowing arbitrary root code execution due to incomplete environment variable sanitization.

    11040190
    121 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Appgnuinetutils---

Explore more