oss-sec mailing list archives

Re: GNU Inetutils talkd buffer overflow with long DNS names.


From: Tristan <TristanInSec () gmail com>
Date: Wed, 19 Aug 2026 00:09:20 +0200

Hi Collin,

Thank you very much for the smooth and professional collaboration on this
issue, and glad to see CVE-2026-19720 assigned.

Best regards,

Tristan Madani
*// Talence Security*


Le sam. 15 août 2026 à 05:16, Collin Funk <collin.funk1 () gmail com> a écrit :

Collin Funk <collin.funk1 () gmail com> writes:

## Timeline

    2026-07-02: Report sent to inetutils-security () gnu org
    2026-07-02: I (Collin Funk) acknowledged the report and asked a few
                questions regarding the issue.
    2026-07-04: Tristan answered those questions.
    2026-07-06: I reproduced the issue updated Tristan with a planned
                timeline for the fix and CVE assignment.
    2026-07-08: Tristan agreed to the timeline and offered to review the
                patch.
    2026-07-11: I wrote the patch and sent it to Tristan.
    2026-07-15: Tristan confirmed the patch worked as expected.
    2026-07-16: Private mail to distros mailing list along with the
patch.
    2026-07-24: I wrote this report and sent it to oss-security.

Note that I also requested a CVE when emailing distros, but haven't
heard back. I'll probably reach out privately to a CNA in a bit, and
will update here once one is assigned.

Red Hat assigned CVE-2026-19720 to this issue yesterday, 2028-08-13.

Collin


Current thread: