CVE-2026-5435Disclosure(gnu / glibc)

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch gnu glibc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-29: 2Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 204-29
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    2 new glibc security advisories https://www.openwall.com/lists/oss-security/2026/04/28/16 GLIBC-SA-2026-0011,CVE-2026-5435: Potential buffer overflow in ns_sprintrrf TSIG handling path GLIBC-SA-2026-0012,CVE-2026-6238: Buffer overread in ns_printrrf with corrupted RDATA field

    Post summary

    The text announces two new glibc security advisories that identify potential buffer overflow and buffer overread vulnerabilities in specific functions, but provides no details on exploits, patches, or active exploitation.

    010102549
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    glibc warns of critical flaws (CVE-2026-5435 & CVE-2026-6238) in deprecated DNS functions. Patch legacy apps to avoid buffer overflows and memory leaks. #glibc #LinuxSecurity #InfoSec #CyberSecurity #BufferOverflow #LegacyCode #OpenSource #SysAdmin #Linux https://securityonline.info/glibc-legacy-dns-vulnerability-cve-2026-5435-patch-guide/ https://t.co/fZChUvri8R

    Post summary

    The tweet announces critical glibc DNS function vulnerabilities and directs users to patch legacy applications to prevent buffer overflows and memory leaks.

    01044605
    12.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more