PT-2026-35713 · Glibc+4 · Glibc+4

·

CVE-2026-5435

·

Published

2026-04-28

·

Updated

2026-08-25

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions glibc versions 2.2 and newer
Description The deprecated functions ns printrrf(), ns printrr(), and fp nquery() fail to enforce the caller-supplied buffer length. This can lead to an out-of-bounds write, which occurs when data is written outside the boundaries of a pre-allocated fixed-length block of memory, specifically when printing TSIG records.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:42694
ALSA-2026:42733
ALSA-2026:42952
AZL-84599
BDU:2026-10479
CVE-2026-5435
ECHO-53D2-A97B-142D
OESA-2026-2592
OESA-2026-2593
OESA-2026-2594
OESA-2026-2767
OPENSUSE-SU-2026:11140-1
OPENSUSE-SU-2026:21228-1
RHSA-2026:12740
RHSA-2026:42694
RHSA-2026:42733
RHSA-2026:42952
SUSE-SU-2026:22453-1
SUSE-SU-2026:22523-1
SUSE-SU-2026:22538-1
SUSE-SU-2026:2987-1
SUSE-SU-2026:3029-1
SUSE-SU-2026:3030-1
USN-8611-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Glibc