#1147395 glibc: CVE-2026-89092

Package:
src:glibc
Source:
src:glibc
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 14:25:03 UTC
Severity:
normal
Tags:
#1147395#5
Date:
2026-09-11 14:38:38 UTC
From:
To:
Hi,

The following vulnerability was published for glibc.

CVE-2026-89092[0]:
| The nscd service in the GNU C Library 2.3.4 onwards may crash due to
| a  stack overflow when a malicious DNS server returns too large a
| response  for a DNS query, resulting in degraded DNS resolution for
| the system.    Exploitation of this bug needs a system that has nscd
| enabled and using  an untrusted DNS server for name resolution, with
| the compromised DNS  server being capable of processing records
| large enough to result in a  stack overflow in an nscd thread
| stack.  During experimentation, bind 9  was unable to handle large
| records, but that could change in future or  with a different name
| server.  In typical installations, nscd is  executed in an isolated
| context as its own user without a shell, due to  which any
| compromise of that service is isolated.    There is a remote
| possibility of nscd cache corruption if an attacker  manages to get
| the stack pointer into a desired point in the heap,  potentially
| resulting in other caches in nscd being overwritten with  corrupt
| data through the stack overflow, until the buggy code path
| eventually results in a crash.    Finally, a crash in nscd may
| result in performance degradation when  resolving names, but it does
| not result in a denial of service.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-89092
https://www.cve.org/CVERecord?id=CVE-2026-89092
[1] https://sourceware.org/bugzilla/show_bug.cgi?id=34624
[2] https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147395#10
Date:
2026-10-03 11:30:56 UTC
From:
To:
Hello,

Bug #1147395 in glibc reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/glibc-team/glibc/-/commit/4fe56589ebc08dc1540960fcde531a0937a08eda
------------------------------------------------------------------------
debian/patches/git-updates.diff: update from upstream stable branch:

* debian/patches/git-updates.diff: update from upstream stable branch:
  - Don't call clearenv() from __libc_setenv_freemem()
  - Fixed a stack overflow in nscd that can be triggered by large DNS
    responses from malicious servers (CVE-2026-89092).  Closes: #1147395.
  - Fix memory corruption on realloc with no mremap.
  - Fix a TOCTOU race condition in the dynamic loader (CVE-2026-86805).
    Closes: #1148727.
  - Fix a stack overflow in the dynamic loader (CVE-2026-95818).  Closes:
    #1148728.
  - Fix one byte overread in POWER8 version of strncasecmp()
    (CVE-2026-97399).  Closes: #1149647
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1147395

#1147395#17
Date:
2026-10-03 14:24:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
glibc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147395@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Aurelien Jarno <aurel32@debian.org> (supplier of updated glibc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 03 Oct 2026 15:48:56 +0200
Source: glibc
Architecture: source
Version: 2.43-7
Distribution: unstable
Urgency: medium
Maintainer: GNU Libc Maintainers <debian-glibc@lists.debian.org>
Changed-By: Aurelien Jarno <aurel32@debian.org>
Closes: 1147395 1148727 1148728 1149647
Changes:
 glibc (2.43-7) unstable; urgency=medium
 .
   [ Aurelien Jarno ]
   * debian/patches/git-updates.diff: update from upstream stable branch:
     - Don't call clearenv() from __libc_setenv_freemem()
     - Fixed a stack overflow in nscd that can be triggered by large DNS
       responses from malicious servers (CVE-2026-89092).  Closes: #1147395.
     - Fix memory corruption on realloc with no mremap.
     - Fix a TOCTOU race condition in the dynamic loader (CVE-2026-86805).
       Closes: #1148727.
     - Fix a stack overflow in the dynamic loader (CVE-2026-95818).  Closes:
       #1148728.
     - Fix one byte overread in POWER8 version of strncasecmp()
       (CVE-2026-97399).  Closes: #1149647
Checksums-Sha1:
 ca6e862d4862c2fb80064b4428f94a5147f2004e 8571 glibc_2.43-7.dsc
 6512e157d3c9e234189b3ec8e6e4386b95d3f6d1 498952 glibc_2.43-7.debian.tar.xz
 cedb452a8777626a0c8b71279a8d24db130f5ce5 9491 glibc_2.43-7_source.buildinfo
Checksums-Sha256:
 a99e5beb8f568765d191f3d0d074cf6b60d2c89dec84f2f4bb70573e52e0a835 8571 glibc_2.43-7.dsc
 9f62b90fb4c7423ed5023698c9014ad0086d26f9b6f46b2a163afcea7e581a02 498952 glibc_2.43-7.debian.tar.xz
 36dc8227785159ff70baeab9baf6df216eb34e2fa22daf165a7ed1c93bef10ed 9491 glibc_2.43-7_source.buildinfo
Files:
 08988dadadab621a7bb7e870de9c90b4 8571 libs required glibc_2.43-7.dsc
 9eefa5604d8c8e2d5d69dc1cbc9b5b1e 498952 libs required glibc_2.43-7.debian.tar.xz
 d7e905ad3d776ff234292056a49832ac 9491 libs required glibc_2.43-7_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUryGlb40+QrX1Ay4E4jA+JnoM2sFAmrBCE0ACgkQE4jA+Jno
M2siFA//ZLLzSVZKx9Ld9cc+gcvzUmyccpMAEXfHDpwhCzW3wD07MZF68pwuY8rM
hERI6akrr/wslO6KlBUYaMV7AnwDeaMIXrWr0Huys+Jr/+roAP6ziAOvtt9txUFv
5uCcs0np2QSfL0dPLf+b5l7PBBsBdBl9RmMgh5xnr3PsV893UlGtLOUsl30vM4CQ
H9fRjo3Duj1JxwZxTFpHG361uwoxhSL7qaqll1kOXLPgfrJSAI+MSBFofSGDdu99
BmeyNNeDR1+4T44BYTEOV0+jjdN7N5hpW7s7PAZTlY+XYsE7AZLNABUIGtRjl3A5
ZKS7kfQNUv3l+f4N6/RL+ZX+P1n/rfp1TePCLQ1mQ+d+qcMD9P8Si8hTORq3Z6ub
FFNqFcFk+VSju1CGd1NQvnps4XazAXnV9scpdFWL6/Nz80p+0L793PGt36fRW23w
qDeoGQv+CkPX4jr2QgWMKIQAi6Lr8Qb3n0YDeBa52O1fVPoYcuLaUiVLBs9AFtsI
fZCMFF7y6xOrjkN7Ivuytn49RUf8w3DpEvwzWs5mLIgVkDDvebEr+xLtT2N5z8iy
Ph9Z+R35a1ugfuat9S5ddJnIVLrSNSEcpQqi8zOPgTtXrqbGDcxieUnneWhx6tyC
XS067hDhAnIkycip7LVqtpiatEVZyGENgQ6NEqKktuUTiBDPnQA=
=pfHI
-----END PGP SIGNATURE-----