Release date:
2026-08-13 05:38:20 UTC
Description:
- CVE-2026-5435: out-of-bounds write in ns_sprintrrf() when printing TSIG
records; the incomplete ns_t_tsig branch emitted the original id with a bare
sprintf() that ignored the caller-supplied buffer length, reachable through
the deprecated ns_sprintrr, ns_printrr and fp_nquery entry points [BZ #34033]
- Add the upstream regression test resolv/tst-ns_sprintrr, which the
CVE-2026-6238 backport deferred to this fix
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.