yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-32772
Component Overview
Vulnerability Overview
Name
CVE-2026-32772
Source
NVD (
link
)
Debian (
link
)
Description
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
CWEs
CWE-669
Published Date
Mar 16, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://www.openwall.com/lists/oss-security/2026/03/13/1
Exploit
https://www.openwall.com/lists/oss-security/2026/03/13/1
Exploit
Analysis
#
Affected Component
Analysis
inetutils
Patched
Vulnerability Ratings
#
3.4
CVSSv31
4.7
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
inetutils
yocto
kirkstone
2.2
Exploitable
inetutils
yocto
master
2.7
Patched
Resolved with patches
#
inetutils (yocto:master)
#
Title
Author
Resolve
1
telnet: don't leak the value of unexported environment
Collin Funk <collin.funk1@gmail.com>
CVE-2026-32772
inetutils (yocto:scarthgap)
#
Title
Author
Resolve
1
telnet: don't leak the value of unexported environment variables
Collin Funk <collin.funk1@gmail.com>
CVE-2026-32772