GNU Vulnerabilities and Affected Products
Vulnerabilities associated with inetutils.
Products
Clear product- Binutils31 vulnerabilities
- grub213 vulnerabilities
- LibreDWG11 vulnerabilities
- PSPP8 vulnerabilities
- elfutils6 vulnerabilities
- Emacs6 vulnerabilities
- Bourne-Again Shell (Bash)5 vulnerabilities
- inetutils5 vulnerabilities
- gawk4 vulnerabilities
- gdb4 vulnerabilities
- cflow3 vulnerabilities
- cpio3 vulnerabilities
- glibc3 vulnerabilities
- GNU C Library (glibc)3 vulnerabilities
- GNU SASL3 vulnerabilities
- Mailman3 vulnerabilities
- Bison2 vulnerabilities
- coreutils2 vulnerabilities
- GCC2 vulnerabilities
- GnuPG2 vulnerabilities
- Guix2 vulnerabilities
- gzip2 vulnerabilities
- Libgcrypt2 vulnerabilities
- ncurses2 vulnerabilities
- patch2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Generated title:GNU inetutils telnet Information Disclosure via NEW_ENVIRON SEND USERVARtelnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR. CWE-669Mar 13, 2026 | CVSS3.4v3.1 | EPSS0.187% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2026-32746CRITICAL | telnetd 2.7 - Buffer Overflowtelnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. CWE-120Mar 13, 2026 | CVSS9.8v3.1 | EPSS23.7% | PoCs9 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28372HIGH | Generated title:GNU inetutils telnetd Privilege Escalation via CREDENTIALS_DIRECTORY Environment Variabletelnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file. CWE-829Feb 27, 2026 | CVSS7.4v3.1 | EPSS0.373% | PoCs6 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-24061CRITICAL | GNU InetUtils Argument Injection Vulnerabilitytelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | CVSS9.8v3.1 | EPSS97.9% | PoCs79 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
GNU inetutils Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011. CWE-120Dec 25, 2011 | CVSS10.0v2.0 | EPSS95% | PoCs9 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |