CVE-2026-5358 Details
Description
Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client or server was ever released for any Linux-based OS distributions and as such this makes the API provisional and unused. Secondly it has been discovered that the NIS+ cold start cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API can only be called with a trusted server from the pre-populated cache. The use of a trusted server means no trust boundary is crossed and this is therefore considered a normal bug.
A buffer overflow vulnerability has been identified in the GNU C Library (glibc) version 2.43 and earlier, within the obsolete nis_local_principal function. This vulnerability arises from the function's potential to overflow a static buffer in the data section. An attacker could exploit this by sending a crafted response to a UDP request generated by nis_local_principal, allowing them to overwrite adjacent static data in the affected application. NIS support has been deprecated in glibc since version 2.26, and applications are encouraged to transition to modern identity and access management services.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Apr 22, 2026 | CVE Rejected | GNU C Library |
| Apr 22, 2026 | CVE Modified | GNU C Library |
| Apr 21, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | GNU C Library |