logo

Legacy Leak: Deprecated GNU C Library Functions Spark New Security Fears

ID: 40c4ec7c-bde6-51c5-8335-fb22d879f49a

STIX ID: report--40c4ec7c-bde6-51c5-8335-fb22d879f49a

Feed Name: securityonline.info

Threat Score
30/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Ddos

...
...

The GNU C Library advisory discloses two vulnerabilities in long-deprecated DNS debugging functions: CVE-2026-5435 (buffer overflow in TSIG handling) and CVE-2026-6238 (buffer overread from malformed RDATA). These flaws can cause application crashes or leak memory contents, but they impact debugging interfaces that have been deprecated since glibc 2.34 and are not used in the normal DNS resolver path; developers are advised to port away from these interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.