oss-sec mailing list archives

Re: GNU Inetutils talkd buffer overflow with long DNS names.


From: Collin Funk <collin.funk1 () gmail com>
Date: Fri, 14 Aug 2026 20:16:28 -0700

Collin Funk <collin.funk1 () gmail com> writes:

## Timeline

    2026-07-02: Report sent to inetutils-security () gnu org
    2026-07-02: I (Collin Funk) acknowledged the report and asked a few
                questions regarding the issue.
    2026-07-04: Tristan answered those questions.
    2026-07-06: I reproduced the issue updated Tristan with a planned
                timeline for the fix and CVE assignment.
    2026-07-08: Tristan agreed to the timeline and offered to review the
                patch.
    2026-07-11: I wrote the patch and sent it to Tristan.
    2026-07-15: Tristan confirmed the patch worked as expected.
    2026-07-16: Private mail to distros mailing list along with the patch.
    2026-07-24: I wrote this report and sent it to oss-security.

Note that I also requested a CVE when emailing distros, but haven't
heard back. I'll probably reach out privately to a CNA in a bit, and
will update here once one is assigned.

Red Hat assigned CVE-2026-19720 to this issue yesterday, 2028-08-13.

Collin


Current thread: