CVE-2023-40303
published 2023-08-14CVE-2023-40303: GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.39%
31.3th percentile
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | inetutils | < inetutils 2:2.4-2+deb12u1 (bookworm) | inetutils 2:2.4-2+deb12u1 (bookworm) |
| gnu | inetutils | <= 2.4 | — |
| gnu | inetutils | >= 0 < 2:2.0-1+deb11u2 | 2:2.0-1+deb11u2 |
| gnu | inetutils | >= 0 < 2:2.4-2+deb12u1 | 2:2.4-2+deb12u1 |
| gnu | inetutils | >= 0 < 2:2.4-3 | 2:2.4-3 |
| gnu | inetutils | >= 0 < 2:2.4-3 | 2:2.4-3 |
| gnu | inetutils | >= 0 < 2:1.9.4-11ubuntu0.2 | 2:1.9.4-11ubuntu0.2 |
| gnu | inetutils | >= 0 < 2:2.2-2ubuntu0.1 | 2:2.2-2ubuntu0.1 |
| gnu | inetutils | >= 0 < 2:1.9.2-1ubuntu0.1~esm2 | 2:1.9.2-1ubuntu0.1~esm2 |
| gnu | inetutils | >= 0 < 2:1.9.4-1ubuntu0.1~esm3 | 2:1.9.4-1ubuntu0.1~esm3 |
| gnu | inetutils | >= 0 < 2:1.9.4-3ubuntu0.1+esm2 | 2:1.9.4-3ubuntu0.1+esm2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
inetutils vulnerabilities
osv·2025-09-28·CVSS 7.8
CVE-2019-0053 [HIGH] inetutils vulnerabilities
inetutils vulnerabilities
Matthew Hickey discovered that Inetutils did not correctly handle certain
escape characters. An attacker could possibly use this issue to cause a
denial of service. (CVE-2019-0053)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-10188)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2022-39028)
It was discovered that Inetutils did not check the return values of set*id
functions. An attacker could possibly use this issue to escalate their
privileges. (CVE-2023-40303)
OSV
inetutils vulnerabilities
osv·2023-08-22·CVSS 7.5
CVE-2022-39028 [HIGH] inetutils vulnerabilities
inetutils vulnerabilities
It was discovered that telnetd in GNU Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash. This issue
only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS (CVE-2022-39028)
It was discovered that Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information,
or execute arbitrary code.
(CVE-2023-40303)
OSV
CVE-2023-40303: GNU inetutils before 2
osv·2023-08-14·CVSS 7.8
CVE-2023-40303 [HIGH] CVE-2023-40303: GNU inetutils before 2
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
GHSA
GHSA-w2mw-45j6-m2cq: GNU inetutils through 2
ghsa_unreviewed·2023-08-14
CVE-2023-40303 [HIGH] CWE-252 GHSA-w2mw-45j6-m2cq: GNU inetutils through 2
GNU inetutils through 2.4 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Ubuntu
Inetutils vulnerabilities
vendor_ubuntu·2025-09-28·CVSS 7.8
CVE-2022-39028 [HIGH] Inetutils vulnerabilities
Title: Inetutils vulnerabilities
Summary: Several security issues were fixed in Inetutils.
Matthew Hickey discovered that Inetutils did not correctly handle certain
escape characters. An attacker could possibly use this issue to cause a
denial of service. (CVE-2019-0053)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to execute arbitrary
code. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-10188)
It was discovered that Inetutils did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial of
service. (CVE-2022-39028)
It was discovered that Inetutils did not check the return values of set*id
functions. An attacker could possibly use this issue to esca
Ubuntu
Inetutils vulnerabilities
vendor_ubuntu·2023-08-22·CVSS 7.5
CVE-2022-39028 [HIGH] Inetutils vulnerabilities
Title: Inetutils vulnerabilities
Summary: Inetutils could be made to crash or execute arbitrary code.
It was discovered that telnetd in GNU Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash. This issue
only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS (CVE-2022-39028)
It was discovered that Inetutils incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information,
or execute arbitrary code.
(CVE-2023-40303)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-40303: inetutils - GNU inetutils before 2.5 may allow privilege escalation because of unchecked ret...
vendor_debian·2023·CVSS 7.8
CVE-2023-40303 [HIGH] CVE-2023-40303: inetutils - GNU inetutils before 2.5 may allow privilege escalation because of unchecked ret...
GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the activities of the process.
Scope: local
bookworm: resolved (fixed in 2:2.4-2+deb12u1)
bullseye: resolved (fixed in 2:2.0-1+deb11u2)
forky: resolved (fixed in 2:2.4-3)
sid: resolved (fixed in 2:2.4-3)
trixie: resolved (fixed in 2:2.4-3)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32772 [HIGH] CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32772 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Source : NVD
## 3.4
Score
Published March 16, 2026
Severity LOW
CNA Score 3.4
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
inetutils
cpe:2.3:a:gnu:inetutils
Sources
NVD
Debian 11 Severity LOW No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity LOW Has Fix Added at: Mar 14, 2026
Echo Severity LOW Has Fix Added at: Mar 14, 2026
Linux
Wiz
CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32746 [HIGH] CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32746 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
Source : NVD
## 9.8
Score
Published March 13, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
krb5-appl-clients
krb5-appl-servers
Sources
Debian 11 Severity CRITICAL No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity
http://www.openwall.com/lists/oss-security/2023/12/30/4https://ftp.gnu.org/gnu/inetutils/https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6https://lists.debian.org/debian-lts-announce/2023/10/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00013.htmlhttps://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.htmlhttp://www.openwall.com/lists/oss-security/2023/12/30/4https://ftp.gnu.org/gnu/inetutils/https://git.savannah.gnu.org/cgit/inetutils.git/commit/?id=e4e65c03f4c11292a3e40ef72ca3f194c8bffdd6https://lists.debian.org/debian-lts-announce/2023/10/msg00013.htmlhttps://lists.debian.org/debian-lts-announce/2023/10/msg00013.htmlhttps://lists.gnu.org/archive/html/bug-inetutils/2023-07/msg00000.html
2023-08-14
Published