The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records. | |
| Title | Potential buffer overflow in ns_sprintrrf TSIG handling path | |
| Weaknesses | CWE-787 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: glibc
Published:
Updated: 2026-04-28T11:58:54.962Z
Reserved: 2026-04-02T17:18:02.654Z
Link: CVE-2026-5435
No data.
Status : Received
Published: 2026-04-28T13:19:22.290
Modified: 2026-04-28T13:19:22.290
Link: CVE-2026-5435
No data.
OpenCVE Enrichment
No data.
Weaknesses