#1149672 inetutils: CVE-2026-95510

Package:
src:inetutils
Source:
src:inetutils
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 15:21:04 UTC
Severity:
normal
Tags:
#1149672#5
Date:
2026-10-02 07:06:58 UTC
From:
To:
Hi,

The following vulnerability was published for inetutils.

CVE-2026-95510[0]:
| use of uninitialized struct sigaction


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-95510
https://www.cve.org/CVERecord?id=CVE-2026-95510
[1] https://www.openwall.com/lists/oss-security/2026/09/26/1
[2] https://codeberg.org/inetutils/inetutils/commit/f756321da9b964fc27fc43652b73913117883047

Regards,
Salvatore

#1149672#10
Date:
2026-10-03 15:02:04 UTC
From:
To:
Hi!

Bug #1149672 that you reported in package inetutils has been fixed
in the debian/pkgs/inetutils.git git repository. You can see the changelog below,
and you can check the diff of the fix at:

https://git.hadrons.org/cgit/debian/pkgs/inetutils.git/diff/?id=05f9df1
    Fix telnetd to not use uninitialized sigaction structures on signal setup

    This could cause crashes leading to a denial of service, or potentially
    lead to code execution on architectures where the sa_restorer
    member is used.

    Reported-Privately-by: Brian Mak <brian.mak@hpe.com>
    Patch-Origin: upstream
    Fixes: CVE-2026-95510
    Closes: #1149672

diff --git a/debian/changelog b/debian/changelog
index 4bf6dad..5f88cf6 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -1,3 +1,13 @@
+inetutils (2:2.8-4) UNRELEASED; urgency=medium
+
+  * Fix telnetd to not use uninitialized sigaction structures when setting up
+    signals. This could cause crashes leading to a denial of service, or
+    potentially lead to code execution on architectures where the sa_restorer
+    member is used. Reported privately by Brian Mak <brian.mak@hpe.com>.
+    Patch taken from upstream. Fixes CVE-2026-95510. (Closes: #1149672)
+
+ -- Guillem Jover <guillem@debian.org>  Sat, 03 Oct 2026 14:11:51 +0200
+
 inetutils (2:2.8-3) unstable; urgency=high

   * Fix talkd to no longer overflow a buffer when writing an announcement for

#1149672#17
Date:
2026-10-03 15:20:06 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
inetutils, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149672@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Guillem Jover <guillem@debian.org> (supplier of updated inetutils package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 03 Oct 2026 14:23:48 +0200
Source: inetutils
Architecture: source
Version: 2:2.8-4
Distribution: unstable
Urgency: high
Maintainer: Guillem Jover <guillem@debian.org>
Changed-By: Guillem Jover <guillem@debian.org>
Closes: 1149672
Changes:
 inetutils (2:2.8-4) unstable; urgency=high
 .
   * Fix telnetd to not use uninitialized sigaction structures when setting up
     signals. This could cause crashes leading to a denial of service, or
     potentially lead to code execution on architectures where the sa_restorer
     member is used. Reported privately by Brian Mak <brian.mak@hpe.com>.
     Patch taken from upstream. Fixes CVE-2026-95510. (Closes: #1149672)
Checksums-Sha1:
 e1cebe353fbad8d6e6a7be035b58627f0e8b20ab 3702 inetutils_2.8-4.dsc
 a1f42cf2f69687d5fbcefde6ad991c41da4b0179 81160 inetutils_2.8-4.debian.tar.xz
 2b0a79262c48e5197d8d8569793394db45f87cc7 12953 inetutils_2.8-4_amd64.buildinfo
Checksums-Sha256:
 aa4a4a7ee153d0961c891f5d5dc094ed28c23f90f198cf8344ac1ff6aea00531 3702 inetutils_2.8-4.dsc
 5c56083c355a617d48f63938680dee062a4585ae90e6dff8059e50a8874b415c 81160 inetutils_2.8-4.debian.tar.xz
 43c616c73be6e03901e7a8e8816f62f6873fd06971428a094cddb5bab2eb81d4 12953 inetutils_2.8-4_amd64.buildinfo
Files:
 717d386f266470c46f9f340c64e1478b 3702 net optional inetutils_2.8-4.dsc
 1d869d27b0330c24b1d15e4757dca2fb 81160 net optional inetutils_2.8-4.debian.tar.xz
 8bf2abaee1b72989fe927e2c17f908bc 12953 net optional inetutils_2.8-4_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

wsG7BAEBCgBvBYJqwRj6CRC5cr8+pK5Xo0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcmfGGBCUHim5S2mjT3rX++CMYl4jBjSNIKG9EFewBqgM
LRYhBE8+dPQ2BQwQ9WlldLlyvz6krlejAACpsg//UjiqansdARUn1eEJp4G1ReAv
xnnQhFdAy8NOoAniW8BEc8FtKb/UMxMkky865epIuo+aHHm2AhiLIOQnnAEVBm5a
5oj0q10LtKGwTsLT9YKYsrwKX9D4C1Y/pQGVxuIvYFaXovcK/ZIrwlEGN13rubcs
QF8gewGFA5Bhz3Ta6emdsIaiZQ98VePS7vq6iPfK1Fqwo9bBOfi1eNbYpcaFwJ3C
oB/jmiZj6n3snQYtVLAwwgOuYcV7FDxPQgp2F7iwalayIDH/gr56icETwqQMQeeA
2uwQIfv52mgZboj3Ynelf/6vY3Qx4pciM2JLjM7FdjTf61iEwtFnkB2qKou6VoRL
iq0ls3N5CxRsba4krKwv38kDsOHwkSx8UmU7xfQlWGb+lscBrkyjx8NQwidwklTU
LE+hjMYeHaJTp8EBilpwHufQKczRRxAGPA4wQ9AdSmInB6VnN5yIwD0T+zNm+x1P
59dEjWdY1AnlVt8CnpTG+gJJ9q3E4HsaVRRejmiszVKZutJ3I12KXTZ4WXL3O/kB
/YdC8r8pJTg4GVxg8jM1cBwPE/KDx7Y3RvGqQCziB+LsIoe/GT8hRQbjoxCLXA52
kyu/8EekBNTcWG+GiXEgg9c3/+xneOftSLtjR2ArLZ9i61w48qJRrWEpRVAwyjHx
JxeYSTvlz+5u4jSceYs=
=HgkE
-----END PGP SIGNATURE-----