Source: inetutils
Version: 2:2.7-3
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: 
https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for inetutils.

CVE-2026-32746[0]:
| telnetd in GNU inetutils through 2.7 allows an out-of-bounds write
| in the LINEMODE SLC (Set Local Characters) suboption handler because
| add_slc does not check whether the buffer is full.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-32746
    https://www.cve.org/CVERecord?id=CVE-2026-32746
[1] https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to