CVE-2026-32746 is a critical out-of-bounds write vulnerability affecting telnetd in GNU inetutils through version 2.7, caused by insufficient buffer checks in the LINEMODE SLC suboption handler. This flaw holds a CVSS score of 9.8 (CRITICAL), indicating a network-exploitable vulnerability with low attack complexity that can lead to complete compromise, including pre-authentication remote code execution. Although no public exploit modules are listed, the vulnerability is designated as "Active" on the Hot List and has garnered significant community and media attention, confirming its severe impact and exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.7CPE match | cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:* | ||
<= 2.7CPE matchmatch criteria | cpe:2.3:a:gnu:inetutils:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
GNU inetutils Buffer Overflow (CVE-2026-32746)
Mar 22, 2026GNU inetutils Buffer Overflow (CVE-2026-32746)
Mar 22, 2026GNU inetutils Buffer Overflow (CVE-2026-32746)
Mar 22, 2026GNU inetutils Buffer Overflow (CVE-2026-32746)
Mar 22, 2026