SB2026081994 - Multiple vulnerabilities in Meinberg LANTIME Operating System Firmware
Published: August 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 61 vulnerabilities.
1) Stack-based buffer overflow (CVE-ID: CVE-2026-32746)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a stack-based buffer overflow in telnetd when processing an SLC suboption with many triplets using function octets greater than 18. A remote attacker can send a specially crafted telnet request to execute arbitrary code.
2) Insufficient entropy (CVE-ID: CVE-2026-41080)
CWE-ID: CWE-331 - Insufficient Entropy
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to insufficient entropy. A remote attacker can supply a specially crafted XML document and flood hashes, leading to a denial of service condition.
3) Resource exhaustion (CVE-ID: CVE-2026-3592)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of self-pointed glue records in BIND resolver processing when resolving names in a specially crafted zone. A remote attacker can induce the resolver to query a specially crafted zone to cause a denial of service.
The issue predominantly affects recursive resolvers. Authoritative-only servers containing only trustworthy zones and names are believed to be unaffected.
4) Use-after-free (CVE-ID: CVE-2026-3593)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to use-after-free in the DNS-over-HTTPS implementation when processing crafted HTTP/2 traffic sent to a DNS-over-HTTPS endpoint. A remote attacker can send crafted HTTP/2 traffic to disclose sensitive information and cause a denial of service.
Both authoritative servers and resolvers are affected.
5) Improper handling of exceptional conditions (CVE-ID: CVE-2026-5946)
CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of non-internet dns class values in named when processing specially crafted dns messages. A remote attacker can send specially crafted dns messages to cause a denial of service.
Affected code paths include recursion, dynamic updates, zone change notifications, and processing of IN-specific record types in non-IN data. Both authoritative servers and resolvers are affected.
6) Use-after-free (CVE-ID: CVE-2026-5947)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in SIG(0) validation when processing a DNS message signed with SIG(0) while the recursive-clients limit is reached during a query flood. A remote attacker can send specially crafted DNS traffic to cause a denial of service.
Both authoritative servers and resolvers are affected.
7) Resource exhaustion (CVE-ID: CVE-2026-5950)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper control of resource consumption in the resolver state machine bad-server handling in BIND 9 when processing queries that trigger specific retry conditions. A remote attacker can send specially crafted queries to cause a denial of service.
Resolvers are affected, while authoritative services are believed to be unaffected.
8) Cleartext transmission of sensitive information (CVE-ID: CVE-2026-4873)
CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to connection reuse ignores TLS requirement. A remote attacker can gain access to sensitive data.
9) Authentication Bypass by Primary Weakness (CVE-ID: CVE-2026-5545)
CWE-ID: CWE-305 - Authentication Bypass by Primary Weakness
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to wrong reuse of HTTP Negotiate authentication connection. A remote attacker can execute arbitrary requests under the wrong user context.
10) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-5773)
CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper reuse of connection for SMB(S) transfers. A remote attacker can gain access to sensitive information on the system.
11) Insufficiently protected credentials (CVE-ID: CVE-2026-6253)
CWE-ID: CWE-522 - Insufficiently Protected Credentials
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information on the system.
The vulnerability exists due to insufficiently protected credentials over redirect-to proxy. A remote attacker can gain access to sensitive information on the system.
12) Origin validation error (CVE-ID: CVE-2026-6276)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to origin validation error within stale custom cookie host. A remote attacker can gain access to sensitive information on the system.
13) Information disclosure (CVE-ID: CVE-2026-6429)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application when reused proxy connection. A remote attacker can gain unauthorized access to sensitive information on the system.
14) Improper Certificate Validation (CVE-ID: CVE-2026-7009)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper certificate validation within OCSP stapling with Apple SecTrust. A remote attacker can cause invalid certificates to be accepted as trusted.
15) Authentication Bypass by Capture-replay (CVE-ID: CVE-2026-7168)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to authentication bypass by capture-replay. A remote attacker can leak and reuse Digest proxy authentication state across proxies to impersonate the client.
16) Heap-based buffer overflow (CVE-ID: CVE-2026-33845)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the DTLS reassembly code when processing crafted DTLS fragments. A remote attacker can send specially crafted DTLS traffic to cause a denial of service or execute arbitrary code.
17) Improper privilege management (CVE-ID: CVE-2026-28372)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper handling of environment variables in telnetd when processing environment options with util-linux login systemd service credentials support. A remote attacker can pass crafted environment variables to escalate privileges.
Exploitation depends on util-linux login(1) support for systemd service credentials.
18) Heap-based buffer overflow (CVE-ID: CVE-2026-33846)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a heap overwrite.
The vulnerability exists due to a heap-based buffer overflow in DTLS fragment handling when processing inconsistent DTLS fragments. A remote attacker can send specially crafted DTLS fragments to cause a heap overwrite.
19) Improper Certificate Validation (CVE-ID: CVE-2026-3832)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate revocation checks.
The vulnerability exists due to improper certificate status validation in OCSP response processing when validating a certificate against a multi-entry OCSP response. A remote attacker can supply a certificate status response with multiple entries to bypass certificate revocation checks.
20) Improper Certificate Validation (CVE-ID: CVE-2026-3833)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass name constraints validation.
The vulnerability exists due to improper certificate validation in name constraints processing when comparing domain names in certificates. A remote attacker can present a specially crafted certificate to bypass name constraints validation.
This issue affects excluded name constraints because domain name comparison was performed case-sensitively, contrary to RFC 5280 section 7.2.
21) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-42009)
CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper implementation of a qsort comparator contract in the DTLS packet sequence number comparator when ordering DTLS packets by sequence numbers. A remote attacker can send DTLS packets with duplicate sequence numbers to cause a denial of service.
22) Improper Authentication (CVE-ID: CVE-2026-42010)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to improper authentication in RSA-PSK username matching when processing usernames containing a NUL character. A remote attacker can supply a specially crafted username to bypass authentication.
23) Improper Certificate Validation (CVE-ID: CVE-2026-42011)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass name constraints during certificate validation.
The vulnerability exists due to improper certificate validation in the name constraints handling logic when processing certificate chains. A remote attacker can present a specially crafted certificate chain to bypass name constraints during certificate validation.
The issue occurs when permitted name constraints are ignored if prior certificate authorities contain only excluded name constraints.
24) Improper Certificate Validation (CVE-ID: CVE-2026-42012)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to misuse certificates beyond their intended purpose.
The vulnerability exists due to improper certificate validation in certificate hostname verification when processing certificates containing URI or SRV Subject Alternative Names. A remote attacker can present a specially crafted certificate to misuse certificates beyond their intended purpose.
Certificates with URI or SRV Subject Alternative Names may incorrectly fall back to checking DNS hostnames against the Common Name.
25) Improper Certificate Validation (CVE-ID: CVE-2026-42013)
CWE-ID: CWE-295 - Improper Certificate Validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass certificate hostname validation.
The vulnerability exists due to improper certificate validation in certificate Subject Alternative Name and Common Name hostname checking when validating certificates with oversized Subject Alternative Names. A remote attacker can present a specially crafted certificate to bypass certificate hostname validation.
26) Use-after-free (CVE-ID: CVE-2026-42014)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in gnutls_pkcs11_token_set_pin() when changing the Security Officer PIN with oldpin set to NULL for a token lacking a protected authentication path. A remote attacker can trigger the vulnerable function call to cause a denial of service.
27) Out-of-bounds write (CVE-ID: CVE-2026-42015)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the PKCS#12 bag handling code when appending to a PKCS#12 bag that already contains 32 elements. A remote attacker can supply crafted PKCS#12 data to cause a denial of service.
28) Out-of-bounds read (CVE-ID: CVE-2026-5260)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in RSA key exchange handling when processing an extremely short premaster secret from a client for a server using an RSA key backed by a PKCS#11 token. A remote attacker can send a specially crafted premaster secret to disclose sensitive information.
Only servers using an RSA key backed by a PKCS#11 token are vulnerable.
29) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-5419)
CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable timing discrepancy in PKCS#7 padding check during decryption when processing ciphertext. A remote attacker can send specially crafted ciphertext to disclose sensitive information.
30) Use-after-free (CVE-ID: CVE-2026-34757)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose heap information and corrupt chunk data.
The vulnerability exists due to use-after-free in png_set_PLTE, png_set_tRNS, and png_set_hIST when passing a pointer returned by the corresponding getter back into the setter on the same png_struct/png_info pair. A remote attacker can pass an aliased pointer to cause the library to read freed memory and copy stale or unrelated heap contents into replacement storage to disclose heap information and corrupt chunk data.
The issue cannot be triggered by a crafted PNG file alone; exploitation requires the application to call the getter and setter in sequence on the same struct pair, and any image containing the relevant chunk is sufficient to set up the internal pointer.
31) Use-after-free (CVE-ID: CVE-2026-44608)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in RPZ zone handling when processing an RPZ XFR reload concurrently with reads of an RPZ zone using 'rpz-nsip' or 'rpz-nsdname' triggers. A remote attacker can trigger a crafted zone transfer timing condition to cause a denial of service.
Only multi-threaded deployments are affected, and local RPZ files do not trigger the vulnerability.
32) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-24061) Exploited
CWE-ID: CWE-88 - Argument Injection or Modification
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation when processing attacker-controlled USER environment variable. A remote non-authenticated attacker can simply connect to the remote server with a specially crafted environment variable and obtain root privileges.
Exploitation example:
USER='-f root' telnet -a <host>
33) Use-after-free (CVE-ID: CVE-2026-28387)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in DANE client code when processing server DANE TLSA records during TLSA-based server authentication. A remote attacker can provide crafted TLSA records to execute arbitrary code.
The issue only affects clients that use both PKIX-TA(0) or PKIX-EE(1) certificate usages together with the DANE-TA(2) certificate usage, and the server must publish a TLSA RRset containing both record types.
34) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-29518)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information and overwrite files outside the module.
The vulnerability exists due to a time-of-check time-of-use symlink race condition in daemon mode path handling when processing file operations on parent path components without chroot. A local user can replace a parent directory component with a symlink between the check and open operation to disclose sensitive information and overwrite files outside the module.
Only daemon configurations with use chroot = no for a module are vulnerable.
35) Improper access control (CVE-ID: CVE-2026-43617)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass hostname-based access controls.
The vulnerability exists due to improper access control in reverse-DNS lookup handling in rsync daemon mode when processing connections after entering the daemon chroot. A remote attacker can connect from a denied hostname and cause hostname-based deny rules to fail open to bypass hostname-based access controls.
Only daemon configurations with daemon chroot = /X are affected when the chroot tree lacks DNS resolution support. IP-based ACLs are unaffected.
36) Integer overflow (CVE-ID: CVE-2026-43618)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an integer overflow in the compressed-token decoder when processing compressed token data from an authenticated daemon connection. A remote user can send crafted compressed-token data to disclose sensitive information.
The disclosed memory may include environment variables, passwords, heap data, and library pointers.
37) Link following (CVE-ID: CVE-2026-43619)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to overwrite files and manipulate filesystem objects outside the module.
The vulnerability exists due to symlink race conditions in path-based system calls in daemon mode when handling path-based system calls without chroot. A local user can replace path components with symlinks during filesystem operations to overwrite files and manipulate filesystem objects outside the module.
Only daemon configurations with use chroot = no for a module are vulnerable.
38) Out-of-bounds read (CVE-ID: CVE-2026-43620)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in recv_files() when processing a crafted file list and transfer record from a malicious server. A remote attacker can send a crafted file list and transfer record to cause a denial of service.
The issue is reachable by any client pulling from a malicious server, and no special options are required on the victim because inc_recurse is the protocol-30+ default.
39) Off-by-one (CVE-ID: CVE-2026-45232)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an off-by-one out-of-bounds stack write in establish_proxy_connection() in socket.c when processing the first response line from an HTTP CONNECT proxy. A remote attacker can return a pathological proxy response line without a newline terminator to cause a denial of service.
The issue is reachable only on the client side when RSYNC_PROXY is set, and the written byte is a fixed \0.
40) Improper privilege management (CVE-ID: CVE-2026-35385)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to create files with unintended setuid or setgid bits.
The vulnerability exists due to improper privilege management in scp(1) when downloading files in legacy (-O) mode as root without the -p flag set. A local privileged user can download a file with crafted mode bits to create files with unintended setuid or setgid bits.
The issue occurs only in legacy mode and only when files are downloaded as root without preserving modes.
41) Input validation error (CVE-ID: CVE-2026-35386)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary shell commands.
The vulnerability exists due to improper input validation in ssh(1) when expanding %-tokens from ssh_config using a user name supplied on the command-line. A local user can supply a specially crafted user name to execute arbitrary shell commands.
Exploitation requires a configuration that uses the %u token in a Match exec block.
42) Improper access control (CVE-ID: CVE-2026-35387)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass configured public key algorithm restrictions.
The vulnerability exists due to improper access control in sshd(8) when applying PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms to ECDSA keys. A remote user can authenticate using an unlisted ECDSA algorithm to bypass configured public key algorithm restrictions.
The issue occurs when one of these directives includes any ECDSA algorithm name.
43) Improper Authorization (CVE-ID: CVE-2026-35388)
CWE-ID: CWE-285 - Improper Authorization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass connection multiplexing confirmation.
The vulnerability exists due to improper access control in ssh(1) when handling proxy mode multiplexing sessions requested with ssh -O proxy under ControlMaster ask or autoask. A local user can initiate a proxy mode multiplexing session to bypass connection multiplexing confirmation.
The issue is limited to proxy mode multiplexing sessions.
44) Improper access control (CVE-ID: CVE-2026-35414)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass principal restrictions in certificate-based authentication.
The vulnerability exists due to improper access control in sshd(8) when matching an authorized_keys principals="" option against a list of principals in a certificate. A remote user can present a specially crafted certificate to bypass principal restrictions in certificate-based authentication.
This condition only affects user-trusted CA keys in authorized_keys and requires multiple principals to be listed, including a certificate principal containing a comma character.
45) Unchecked Return Value (CVE-ID: CVE-2026-31790)
CWE-ID: CWE-252 - Unchecked Return Value
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to incorrect failure handling in RSA KEM RSASVE encapsulation when processing an attacker-supplied invalid RSA public key with EVP_PKEY_encapsulate(). A remote attacker can supply an invalid RSA public key to disclose sensitive information.
The issue affects applications using RSA/RSASVE encapsulation without validating the supplied public key first.
46) NULL pointer dereference (CVE-ID: CVE-2026-28388)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to NULL pointer dereference in delta CRL processing during X.509 certificate verification when processing a malformed delta CRL that contains a Delta CRL Indicator extension but lacks a CRL Number extension. A remote attacker can provide a malformed CRL to cause a denial of service.
Exploitation requires delta CRL processing to be enabled in the verification context and the certificate or base CRL to indicate freshest CRL processing.
47) Out-of-bounds read (CVE-ID: CVE-2025-10158)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform a denial of service attack.
The vulnerability exists due to a boundary condition within the send_files() function in sender.c. A remote user can trigger an out-of-bounds read error and perform a denial of service attack.
48) NULL pointer dereference (CVE-ID: CVE-2026-28389)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to NULL pointer dereference in CMS KeyAgreeRecipientInfo processing when processing a crafted CMS EnvelopedData message with a missing optional parameters field. A remote attacker can send a crafted CMS message to cause a denial of service.
Applications and services that call CMS_decrypt() on untrusted input, such as S/MIME processing or CMS-based protocols, are affected.
49) NULL pointer dereference (CVE-ID: CVE-2026-28390)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to NULL pointer dereference in CMS KeyTransportRecipientInfo processing when processing a crafted CMS EnvelopedData message using RSA-OAEP with a missing optional parameters field. A remote attacker can send a crafted CMS message to cause a denial of service.
Applications and services that call CMS_decrypt() on untrusted input, such as S/MIME processing or CMS-based protocols, are affected.
50) Heap-based buffer overflow (CVE-ID: CVE-2026-31789)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to heap-based buffer overflow in hexadecimal conversion when converting an excessively large OCTET STRING value from an untrusted X.509 certificate to a hexadecimal string on 32-bit platforms. A remote attacker can supply a crafted X.509 certificate to execute arbitrary code.
Only 32-bit platforms are affected, and exploitation requires printing or logging untrusted X.509 certificates containing an OCTET STRING value larger than 1 gigabyte.
51) Heap-based buffer overflow (CVE-ID: CVE-2026-32792)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in Unbound's DNSCrypt packet reading procedure when processing a crafted DNSCrypt query. A remote attacker can send a specially crafted DNSCrypt query to cause a denial of service.
Only installations compiled with DNSCrypt support are vulnerable. The crafted query's decrypted plaintext consists entirely of 0x00 bytes and lacks the expected 0x80 marker. A crash depends on the underlying memory allocator and memory layout.
52) Use-after-free (CVE-ID: CVE-2026-33278)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service and potentially execute arbitrary code.
The vulnerability exists due to use-after-free in Unbound DNSSEC validator when processing validation state for DS sub-queries after deep-copying response messages during NSEC3 computational budget exhaustion. A remote attacker can control a malicious signed zone and query a vulnerable resolver to cause a denial of service and potentially execute arbitrary code.
Exploitation requires control of a malicious signed zone.
53) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-40622)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to extend the ghost domain window.
The vulnerability exists due to improper handling of cached parent-side referral NS records in Unbound when processing NS queries for a ghost zone. A remote attacker can control a ghost zone and trigger replacement of an expired parent-side referral NS rrset with the child-side apex NS rrset to extend the ghost domain window.
In configurations with 'harden-referral-path: yes', no client NS query is required because the resolver performs that query implicitly.
54) Resource exhaustion (CVE-ID: CVE-2026-41292)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in EDNS option parsing when handling queries with long lists of EDNS options. A remote attacker can send specially crafted queries with too many EDNS options to cause a denial of service.
Coordinated attacks can degrade service by tying up Unbound threads while internal data structures for the options are being created.
55) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-42534)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper state management in Unbound jostle logic when processing duplicate queries while resolving queries through a slow or malicious authoritative name server. A remote user can send repeated queries for names served by a controlled slow-responding domain name server to cause a denial of service.
Cache and local data response performance remains unaffected. Exploitation requires the resolver to reach its configured query-per-thread limit, and coordinated attacks can degrade resolution into denial of resolution service.
56) Resource exhaustion (CVE-ID: CVE-2026-42923)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in Unbound's DNSSEC validator negative cache handling for DS records when processing DNSSEC-signed zones with NSEC3 records using high iteration counts for child delegations. A remote attacker can control a DNSSEC-signed zone and query a vulnerable Unbound resolver to cause a denial of service.
A global lock for the negative cache may be held for the duration of the hashing, blocking other threads that need to consult the negative cache.
57) Heap-based buffer overflow (CVE-ID: CVE-2026-42944)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the EDNS option encoder when processing queries containing multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options. A remote attacker can send a specially crafted query to cause a denial of service.
Only instances with the relevant EDNS options enabled are vulnerable.
58) Access of Uninitialized Pointer (CVE-ID: CVE-2026-42959)
CWE-ID: CWE-824 - Access of Uninitialized Pointer
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use of an uninitialized pointer in the DNSSEC validator when constructing chase-reply messages for validation. A remote attacker can provide a malicious upstream reply to cause a denial of service.
Exploitation requires control of a DNSSEC-signed domain and can be triggered with a single query using a DNAME chain with unsigned CNAMEs and a response containing unsigned AUTHORITY records alongside signed ADDITIONAL glue records.
59) Insufficient verification of data authenticity (CVE-ID: CVE-2026-42960)
CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity
CVSSv4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to poison Unbound's DNS cache.
The vulnerability exists due to improper cache validation in processing authority and additional section RRSets when handling spoofed DNS replies or fragmented responses. A remote attacker can inject non-NS RRSets accompanied by related address records to poison Unbound's DNS cache.
Exploitation requires the ability to attach malicious records to a reply, such as through packet spoofing or fragmentation attacks.
60) Resource exhaustion (CVE-ID: CVE-2026-44390)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in name compression handling for downstream replies when processing malicious upstream responses with very large RRsets whose records do not share a suffix above the root. A remote attacker can query Unbound for specially crafted contents of a malicious zone to cause a denial of service.
The issue can lock the CPU while the reply packet is being completed, leading to degraded performance before service disruption.
61) Memory leak (CVE-ID: CVE-2026-3039)
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the GSS-API TKEY negotiation handling in BIND 9 when processing maliciously constructed packets. A remote attacker can send specially crafted packets to cause a denial of service.
Only servers configured to use TKEY-based authentication via GSS-API tokens are vulnerable.
Remediation
Install update from vendor's website.