yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2026-57053
Component Overview
Vulnerability Overview
Name
CVE-2026-57053
Source
NVD (
link
)
Debian (
link
)
Description
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
CWEs
CWE-1284
CWE-1284
Published Date
Jun 23, 2026
Updated Date
Jun 29, 2026
Workaround
-
Advisories
https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html
Exploit
https://lists.gnu.org/archive/html/help-libidn/2026-06/msg00001.html
Mailing List
Analysis
#
Affected Component
Analysis
libidn
Exploitable
Vulnerability Ratings
#
4
CVSSv31
2.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libidn
buildroot
2025.02.x
1.42
Exploitable
libidn
buildroot
master
1.43
Exploitable
libidn
openwrt
master
1.44-r1
Not Affected
libidn
openwrt
openwrt-25.12
1.42-r1
Exploitable
libidn
yocto
master
1.44
Not Affected
libidn
yocto
scarthgap
1.41
Patched
Resolved with patches
#
libidn (yocto:scarthgap)
#
Title
Author
Resolve
1
Guard against read-out-bounds on some xn-- strings
Simon Josefsson <simon@josefsson.org>
CVE-2026-57053