CVE-2026-5358Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API provisional and unused. Secondly it has been discovered that the NIS+ cold start cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API can only be called with a trusted server from the pre-populated cache. The use of a trusted server means no trust boundary is crossed and this is therefore considered a normal bug.

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-28: 104-2004-2104-28
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-212
Disclosure1Patch1
2026-04-281
Patch1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    glibc version 2.43 and older face heap overflows and memory leaks. Learn about CVE-2026-5358, CVE-2026-5450, and CVE-2026-5928. Update your Linux systems now. #glibc #LinuxSecurity #CyberSecurity #InfoSec #OpenSource #CVE #Vulnerability #SysAdmin https://securityonline.info/glibc-vulnerabilities-2026-linux-security-flaws/ https://t.co/RnpzeVqzJk

    Post summary

    The tweet announces heap‑overflow and memory‑leak vulnerabilities affecting glibc 2.43 and older (CVE-2026-5358, CVE-2026-5450, CVE-2026-5928) and urges users to update their Linux systems.

    22081787
    12.5K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    3 new glibc SAs https://www.openwall.com/lists/oss-security/2026/04/20/9 GLIBC-SA-2026-0008,CVE-2026-5358: Static buffer overflow in deprecated nis_local_principal GLIBC-SA-2026-0009,CVE-2026-5450: scanf %mc off-by-one heap buffer overflow GLIBC-SA-2026-0010,CVE-2026-5928: Potential buffer under-read in ungetwc

    Post summary

    Three new glibc security advisories are announced, outlining CVE‑assigned buffer overflow flaws, with no current evidence of exploitation or available fixes.

    00040399
    4.7K followersView on X
  • Vito Botta@vitobotta
    Patch

    Just read about three recent CVEs in glibc, the library that underpins basically every Linux system on the planet. The scariest one is CVE-2026-5450, a heap buffer overflow in scanf with the %mc format specifier, CVSS 9.8. Versions 2.7 through 2.43 are affected. That's decades of glibc releases. Then there's CVE-2026-5358, a buffer overflow in the obsolete nis_local_principal function, and CVE-2026-5928, a buffer under-read in ungetwc that can leak heap data. Patch your systems. When glibc has bugs, we can assume that everything built on top of it has potential bugs.

    Post summary

    The post highlights three recent high‑severity glibc CVEs and urges users to patch their systems, without providing PoC or exploit code.

    0000092
    956 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5358 The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof … https://www.cve.org/CVERecord?id=CVE-2026-5358

    Post summary

    The text announces CVE-2026-5358, detailing a buffer overflow in the GNU C Library's obsolete nis_local_principal function that could enable spoofing, with no PoC, exploit, active use, or patch information provided.

    0000091
    57.2K followersView on X

Explore more