CVE-2026-95510: GNU Inetutils: use of uninitialized struct sigaction
GNU Inetutils CVE-2026-95510 uses an uninitialized sigaction in rlogin, rlogind, and telnetd, risking crashes.
Collin Funk disclosed CVE-2026-95510 in GNU Inetutils after Brian Mak privately reported a bug in libinetutils on 2026-09-14. A function used by rlogin, rlogind, and telnetd uses an uninitialized struct sigaction. Mak saw telnetd crash, which can cause denial of service, and maintainers also discussed possible code execution on some platforms. Possible exploits are not fully clear, and no in-the-wild exploitation is reported.
- Uninitialized struct sigaction in libinetutils affects rlogin, rlogind, and telnetd.
- Brian Mak observed telnetd crashing, which can cause denial of service.
- Maintainers also discussed possible code execution; exploitability remains unclear.
- No in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-95510 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by Collin Funk on Sep 25 On 2026-09-14, Brian Mak privately reported a security issue with a function defined in libinetutils, a part of GNU Inetutils. The function is used by rlogin, rlogind, and telnetd. The possible exploits using the bug aren't entirely clear. Brian noticed the bug from 'telnetd' crashing, which could lead to a denial of service. However, from our discussions, we were also concerned about the possibility of code execution on platforms...
This source does not provide full text. Read it at seclists.org.