CVE-2026-32746: critical vulnerability in GNU inetutils
Published · Updated
No sign of exploitation. It has a public proof of concept.
The telnetd service in GNU inetutils has a critical flaw where it can write data outside its designated memory buffer when handling certain telnet commands. This allows attackers to crash the server or potentially execute malicious code by sending specially crafted telnet requests.
CVE-2026-32746 is a stack-based buffer overflow in the LINEMODE SLC suboption handler of telnetd (GNU inetutils ≤2.7). The add_slc function fails to validate buffer boundaries before writing, enabling remote attackers to trigger out-of-bounds memory writes via crafted telnet protocol messages, resulting in denial of service or code execution without authentication.
In the same product, most dangerous first.