PT-2026-33850 · Glibc · Glibc

·

CVE-2026-5358

·

Published

2026-04-20

·

Updated

2026-04-28

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions glibc versions prior to 2.44
Description The obsolete nis local principal() function may overflow a buffer in the data section. This allows an attacker to spoof a crafted response to a UDP request generated by this function and overwrite neighboring static data in the requesting application. NIS (Network Information Service) is a legacy system for distributing configuration data across a network.
Recommendations Update to a version newer than 2.43. Port applications away from NIS to more modern identity and access management services.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5358
ECHO-83A2-A00B-6C15

Affected Products

Glibc