yocto ▾
›
master ▾
›
vulnerability
›
CVE-2026-32746
Component Overview
Vulnerability Overview
Name
CVE-2026-32746
Source
NVD (
link
)
Debian (
link
)
Description
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
CWEs
CWE-120
Published Date
Mar 13, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html
Exploit
https://www.openwall.com/lists/oss-security/2026/03/12/4
Mailing List
http://www.openwall.com/lists/oss-security/2026/03/14/1
Mailing List
https://github.com/watchtowrlabs/watchtowr-vs-telnetd-CVE-2026-32746
Third Party Advisory
Analysis
#
Affected Component
Analysis
inetutils
Patched
Vulnerability Ratings
#
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
inetutils
yocto
kirkstone
2.2
Exploitable
inetutils
yocto
scarthgap
2.5
Patched
Resolved with patches
#
inetutils (yocto:master)
#
Title
Author
Resolve
1
telnetd: fix stack buffer overflow processing SLC suboption
Collin Funk <collin.funk1@gmail.com>
CVE-2026-32746
inetutils (yocto:scarthgap)
#
Title
Author
Resolve
1
telnetd: fix stack buffer overflow processing SLC suboption triplets
Collin Funk <collin.funk1@gmail.com>
CVE-2026-32746