Source: glibc Version: 2.43-4 Severity: important Tags: security upstream Forwarded: https://sourceware.org/bugzilla/show_bug.cgi?id=34624 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for glibc. CVE-2026-89092[0]: | The nscd service in the GNU C Library 2.3.4 onwards may crash due to | a stack overflow when a malicious DNS server returns too large a | response for a DNS query, resulting in degraded DNS resolution for | the system. Exploitation of this bug needs a system that has nscd | enabled and using an untrusted DNS server for name resolution, with | the compromised DNS server being capable of processing records | large enough to result in a stack overflow in an nscd thread | stack. During experimentation, bind 9 was unable to handle large | records, but that could change in future or with a different name | server. In typical installations, nscd is executed in an isolated | context as its own user without a shell, due to which any | compromise of that service is isolated. There is a remote | possibility of nscd cache corruption if an attacker manages to get | the stack pointer into a desired point in the heap, potentially | resulting in other caches in nscd being overwritten with corrupt | data through the stack overflow, until the buggy code path | eventually results in a crash. Finally, a crash in nscd may | result in performance degradation when resolving names, but it does | not result in a denial of service. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-89092 https://www.cve.org/CVERecord?id=CVE-2026-89092 [1] https://sourceware.org/bugzilla/show_bug.cgi?id=34624 [2] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

