CVE-2026-32746
CRITICALGNU inetutils through 2.7 - Buffer Overflow
Title source: llmDescription
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
Exploits (5)
nomisec
SCANNER
by watchtowrlabs · poc
https://github.com/watchtowrlabs/watchtowr-vs-telnetd-CVE-2026-32746
References (5)
Scores
CVSS v3
9.8
EPSS
0.0003
EPSS Percentile
9.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-120
Status
published
Products (1)
GNU/inetutils
< 2.7
Published
Mar 13, 2026
Tracked Since
Mar 14, 2026