CVE-2026-57053 Details
Description
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
A vulnerability in GNU Libidn prior to version 1.44 allows for out-of-bounds reads of uninitialized memory in the ToUnicode APIs. This issue arises from improper handling in the idna_to_unicode_internal function, which can lead to the reading of stale stack bytes. The vulnerability is not present in Libidn2.
Users are advised to upgrade to GNU Libidn version 1.44 or later, or to apply the available patch to their current version. Instructions for applying the patch can be found in the GNU Libidn Security Advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html | [email protected] | ExploitMailing List |
| https://lists.gnu.org/archive/html/help-libidn/2026-06/msg00001.html | [email protected] | Mailing List |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1284 | Improper Validation of Specified Quantity in Input | [email protected] |
| CWE-1284 | Improper Validation of Specified Quantity in Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu libidn | >= 0.1.15, < 1.44 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | New CVE Received | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |