← Back to browse · API

CVE-2026-32746

Severity
CRITICAL
CVSS
9.8
EPSS
0.23674
Risk score
47.49
CISA KEV
No
PoC
Yes
Published
2026-03-13
Modified
2026-03-23
First seen
2026-08-07
Aliases
EUVD-2026-12065
Products
GNU:Inetutils 0 ≤2.7
Sources
euvd EUVD-2026-12065
github 95e7bcf292d5f1e0699a814c|CVE-2026-32746

Description

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

References