CVE-2026-95510: GNU Inetutils: use of uninitialized struct sigaction
GNU Inetutils CVE-2026-95510 uses an uninitialized sigaction in rlogin, rlogind, and telnetd, risking crashes.
Collin Funk disclosed CVE-2026-95510 in GNU Inetutils after Brian Mak privately reported a bug in libinetutils on 2026-09-14. A function used by rlogin, rlogind, and telnetd uses an uninitialized struct sigaction. Mak saw telnetd crash, which can cause denial of service, and maintainers also discussed possible code execution on some platforms. Possible exploits are not fully clear, and no in-the-wild exploitation is reported.
38