From: Siddhesh Poyarekar <siddhesh@gotplt.org>
To: Carlos O'Donell <carlos@redhat.com>, libc-alpha@sourceware.org
Subject: Re: [PATCH] Add advisory text for CVE-2026-5435
Date: Mon, 27 Apr 2026 18:18:28 -0400 [thread overview]
Message-ID: <c54559a5-251f-4bdd-bea7-96252fee475e@gotplt.org> (raw)
In-Reply-To: <20260427215230.629899-1-carlos@redhat.com>
On 27/04/2026 17:52, Carlos O'Donell wrote:
> ---
> advisories/GLIBC-SA-2026-0011 | 24 ++++++++++++++++++++++++
> 1 file changed, 24 insertions(+)
> create mode 100644 advisories/GLIBC-SA-2026-0011
LGTM.
Reviewed-by: Siddhesh Poyarekar <siddhesh@gotplt.org>
>
> diff --git a/advisories/GLIBC-SA-2026-0011 b/advisories/GLIBC-SA-2026-0011
> new file mode 100644
> index 0000000000..6c1e50fa74
> --- /dev/null
> +++ b/advisories/GLIBC-SA-2026-0011
> @@ -0,0 +1,24 @@
> +Potential buffer overflow in ns_sprintrrf TSIG handling path
> +
> +The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the
> +GNU C Library version 2.2 and newer fail to enforce the caller-supplied
> +buffer length, and can result in an out-of-bounds write when printing
> +TSIG records.
> +
> +A defect in the TSIG case handling within ns_sprintrrf performs a
> +formatted write using sprintf without checking the remaining buffer
> +length, and may write up to 6 bytes past the end of the buffer. If the
> +library is compiled with assertions, and the out-of-bounds write doesn't
> +terminate the process, then a subsequent check for "len <= *buflen" will
> +trigger an assertion failure.
> +
> +These functions are for debugging only and hence not in the default path
> +of code executed by the DNS resolver. Further, they have been deprecated
> +since version 2.34 (2021-08-02) and should not be used by any new
> +applications. Applications should consider porting away from these
> +interfaces since they may be removed in future versions.
> +
> +CVE-Id: CVE-2026-5435
> +Public-Date: 2026-04-02
> +Vulnerable-Commit: b43b13ac2544b11f35be301d1589b51a8473e32b (2.2)
> +Reported-by: shinobu
next prev parent reply other threads:[~2026-04-27 22:18 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-04-27 21:52 Carlos O'Donell
2026-04-27 22:18 ` Siddhesh Poyarekar [this message]
2026-04-28 4:47 ` Florian Weimer
2026-04-28 11:38 ` Carlos O'Donell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c54559a5-251f-4bdd-bea7-96252fee475e@gotplt.org \
--to=siddhesh@gotplt.org \
--cc=carlos@redhat.com \
--cc=libc-alpha@sourceware.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).