CVE-2026-5435: Potential buffer overflow in ns_sprintrrf TSIG handling path
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5435?
CVE-2026-5435 is classified as a high severity vulnerability due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-2026-5435?
To fix CVE-2026-5435, update to the latest version of the GNU C Library that addresses the buffer overflow issue.
What are the potential impacts of CVE-2026-5435?
The impacts of CVE-2026-5435 include the risk of denial of service or potentially arbitrary code execution on affected systems.
Which versions of GNU C Library are affected by CVE-2026-5435?
CVE-2026-5435 affects GNU C Library versions 2.2 and newer.
Is there a workaround for CVE-2026-5435?
Currently, the best practice is to apply the patch or upgrade to a secure version of the GNU C Library, as no specific workaround is recommended.