CVE-2026-5435
published 2026-04-28CVE-2026-5435: The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length…
PriorityP341high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.24%
14.8th percentile
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | glibc | — | — |
| gnu | glibc | >= 2.2 | — |
| the_gnu_c_library | glibc | 2.2 – * | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU C Library up to 2.2 ns_printrrf/ns_printrr/fp_nquery out-of-bounds write
vuldb·2026-04-28
CVE-2026-5435 [CRITICAL] GNU C Library up to 2.2 ns_printrrf/ns_printrr/fp_nquery out-of-bounds write
A vulnerability marked as critical has been reported in GNU C Library up to 2.2. Affected by this issue is the function ns_printrrf/ns_printrr/fp_nquery. This manipulation causes out-of-bounds write.
This vulnerability is registered as CVE-2026-5435. Remote exploitation of the attack is possible. No exploit is available.
GHSA
GHSA-32rw-r8mp-pw42: The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2
ghsa_unreviewed·2026-04-28
CVE-2026-5435 [HIGH] CWE-787 GHSA-32rw-r8mp-pw42: The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
Red Hat
glibc: glibc: Out-of-bounds write via TSIG record processing
vendor_redhat·2026-04-28·CVSS 5.9
CVE-2026-5435 [MEDIUM] CWE-120 glibc: glibc: Out-of-bounds write via TSIG record processing
glibc: glibc: Out-of-bounds write via TSIG record processing
A flaw was found in glibc, the GNU C Library. Specifically, deprecated functions responsible for printing TSIG (Transaction Signature) records fail to properly manage memory buffers. This oversight can lead to an out-of-bounds write when processing specially crafted TSIG records. An attacker could exploit this to cause a denial of service or potentially execute arbitrary code.
Package: glibc (Red Hat Enterprise Linux 10) - Fix deferred
Package: compat-glibc (Red Hat Enterprise Linux 6) - Fix deferred
Package: glibc (Red Hat Enterprise Linux 6) - Fix deferred
Package: compat-glibc (Red Hat Enterprise Linux 7) - Fix deferred
Package: glibc (Red Hat Enterprise Linux 7) - Fix deferred
Package: glibc (Red Hat Enterprise Linux 8
No detection rules found.
No public exploits indexed.
2026-04-28
Published