yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-5435
Component Overview
Vulnerability Overview
Name
CVE-2026-5435
Source
NVD (
link
)
Debian (
link
)
Description
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
CWEs
CWE-787
Published Date
Apr 28, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u
Third Party Advisory
https://sourceware.org/bugzilla/show_bug.cgi?id=34033
Issue Tracking
Analysis
#
Affected Component
Analysis
glibc
Exploitable
Vulnerability Ratings
#
7.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
glibc
buildroot
2025.02.x
2.41-137-gb676adadbc1f5fb2f31bc484a7628cca89ae6f22
Exploitable
glibc
buildroot
master
2.43-27-g4070d808bea1c077eb7e7d52b52b91cae98205d5
Exploitable
glibc
yocto
master
2.43+git
Exploitable
glibc
yocto
scarthgap
2.39+git
Exploitable