CVE-2026-5358
published 2026-04-20CVE-2026-5358: The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker…
PriorityP422critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof a crafted response to a UDP request generated by this function and overwrite neighboring static data in the requesting application.
NIS support is obsolete and has been deprecated in the GNU C Library since version 2.26 and is only maintained for legacy usage. Applications should port away from NIS to more modern identity and access management services.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | glibc | — | — |
| the_gnu_c_library | glibc | <= 2.43 | — |
CVSS provenance
cvelistv5v3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU C Library up to 2.43 UDP nis_local_principal buffer overflow (Nessus ID 308170 / WID-SEC-2026-1190)
vuldb·2026-04-21
CVE-2026-5358 [CRITICAL] GNU C Library up to 2.43 UDP nis_local_principal buffer overflow (Nessus ID 308170 / WID-SEC-2026-1190)
A vulnerability classified as critical has been found in GNU C Library up to 2.43. This affects the function nis_local_principal of the component UDP Handler. Performing a manipulation results in buffer overflow.
This vulnerability is identified as CVE-2026-5358. The attack is only possible with local access. There is not any exploit available.
CVEList
Static buffer overflow in deprecated nis_local_principal
cvelistv5·2026-04-20·CVSS 9.1
CVE-2026-5358 [CRITICAL] CWE-120 Static buffer overflow in deprecated nis_local_principal
Static buffer overflow in deprecated nis_local_principal
The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof a crafted response to a UDP request generated by this function and overwrite neighboring static data in the requesting application.
NIS support is obsolete and has been deprecated in the GNU C Library since version 2.26 and is only maintained for legacy usage. Applications should port away from NIS to more modern identity and access management services.
GHSA
GHSA-jj2g-xq7w-gf88: The obsolete nis_local_principal function in the GNU C Library version 2
ghsa_unreviewed·2026-04-20
CVE-2026-5358 [CRITICAL] CWE-120 GHSA-jj2g-xq7w-gf88: The obsolete nis_local_principal function in the GNU C Library version 2
The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof a crafted response to a UDP request generated by this function and overwrite neighboring static data in the requesting application.
NIS support is obsolete and has been deprecated in the GNU C Library since version 2.26 and is only maintained for legacy usage. Applications should port away from NIS to more modern identity and access management services.
Red Hat
glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function
vendor_redhat·2026-04-20·CVSS 8.2
CVE-2026-5358 [HIGH] CWE-120 glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function
glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function
A flaw was found in the GNU C Library (glibc). The obsolete `nis_local_principal` function contains a buffer overflow vulnerability. A remote attacker could exploit this by spoofing a crafted response to a User Datagram Protocol (UDP) request. This could allow the attacker to overwrite static data in the requesting application, potentially leading to data corruption or a denial of service.
Mitigation: To mitigate this issue, ensure that Network Information Service (NIS) is not in use on affected systems. NIS is an obsolete service and its use is deprecated in modern Red Hat Enterprise Linux environments. If NIS is not required, disable any services or applications that rely on `nis_loca
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5358 glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function [fedora-all]
bugzilla·2026-04-22
CVE-2026-5358 [HIGH] CVE-2026-5358 glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function [fedora-all]
CVE-2026-5358 glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5358 glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function
bugzilla·2026-04-20
CVE-2026-5358 [HIGH] CVE-2026-5358 glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function
CVE-2026-5358 glibc: glibc: Data corruption or denial of service via buffer overflow in nis_local_principal function
The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof a crafted response to a UDP request generated by this function and overwrite neighboring static data in the requesting application.
NIS support is obsolete and has been deprecated in the GNU C Library since version 2.26 and is only maintained for legacy usage. Applications should port away from NIS to more modern identity and access management services.
2026-04-20
Published