CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-95510: GNU Inetutils: use of uninitialized struct sigaction

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8636

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-95510: GNU Inetutils: use of uninitialized struct sigaction

A use-of-uninitialized-memory vulnerability, CVE-2026-95510, was discovered in GNU Inetutils' libinetutils library on September 14, 2026, affecting functions used by rlogin, rlogind, and telnetd. The vulnerability can cause telnetd to crash, leading to denial of service, and on some platforms may enable code execution.

Why it matters: Administrators running rlogin, rlogind, or telnetd services should assess exposure and apply patches when available, as the vulnerability can disrupt service availability and potentially allow remote compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary