ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 2 sources: “GNU C Library security advisory batch discloses strfmon buffer overflow and DNS stub resolver abort” — merged summary and timeline →

The GNU C Library security advisories update for 2026-09-17

mediumVulnerabilityimportance 45
AI summary · glm-5.3-flash

GNU C Library advisory describes a DNS stub resolver assertion failure that aborts processes when search domains reach roughly 200 characters in glibc 2.26-2.44.

GLIBC-SA-2026-0021 details an assertion failure in the glibc DNS stub resolver. Systems running glibc versions 2.26 through 2.44 abort when the search list in /etc/resolv.conf or the LOCALDOMAIN environment variable contains a domain of roughly 200 characters or more. The advisory was published as part of the GNU C Library security update batch on 2026-09-17.

  • Affects glibc versions 2.26 through 2.44
  • Triggered by search domains of roughly 200+ characters in resolv.conf or LOCALDOMAIN
  • Impact is process abort (denial of service), not code execution
VendorsGNU
Full article

Posted by Adhemerval Zanella Netto on Sep 17 The following security advisories have been published: GLIBC-SA-2026-0021: =================== Assertion failure in the DNS stub resolver with a long search domain Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process. The...

This source does not provide full text. Read it at seclists.org.