CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-32746

CVE-2026-32746: Pre-Authentication Remote Code Execution via BSS Overflow in GNU Inetutils telnetd

Alon Barad
Alon Barad
Software Engineer

Mar 26, 2026·8 min read·186 visits

Executive Summary (TL;DR)

Unauthenticated remote code execution as root affects GNU Inetutils telnetd up to version 2.7 due to a missing bounds check in the slc.c module.

A 32-year-old pre-authentication buffer overflow vulnerability exists in the GNU Inetutils telnetd daemon. The flaw resides in the LINEMODE SLC suboption handler, allowing remote attackers to achieve arbitrary code execution as the root user by overflowing a fixed-size BSS buffer during the initial Telnet handshake.

Vulnerability Overview

The GNU Inetutils package provides a suite of common network administration utilities, including the telnetd server daemon. Security researchers identified a critical vulnerability within the legacy codebase originating from the 1994 BSD Telnet implementation. The flaw affects all versions of GNU Inetutils up to and including version 2.7. The widespread integration of this code means the vulnerability impacts numerous operating systems, including major Linux distributions, FreeBSD, NetBSD, macOS, and various embedded network appliances.

The vulnerability is classified as a Stack/BSS-based Buffer Overflow (CWE-120, CWE-787). The defect resides specifically in the LINEMODE Set Local Characters (SLC) suboption handler. The daemon fails to validate the size of incoming network data before copying it into a fixed-size buffer located in the uninitialized data segment (BSS). This oversight permits out-of-bounds write operations.

The telnetd service exposes a pre-authentication network interface to process incoming connections. An unauthenticated remote attacker interacts with this vulnerable code path during the initial protocol handshake. The attack requires no prior authorization or valid credentials on the target system. The network vector allows exploitation across internal networks and the public internet.

Successful exploitation results in arbitrary remote code execution. Because the telnetd daemon typically executes with elevated system privileges, the attacker gains complete control over the host OS as the root user. The vulnerability carries a CVSS v3.1 base score of 9.8, reflecting its critical severity and ease of remote exploitation.

Root Cause Analysis

The core vulnerability exists in the telnetd/slc.c file during the processing of LINEMODE SLC negotiation. The server maintains a statically allocated buffer named slcbuf to store SLC triplets during the protocol handshake. This buffer has a fixed capacity of 108 bytes. The server tracks the current memory offset for incoming data using a global pointer named slcptr.

The add_slc function processes incoming triplets consisting of a function code, a flag, and a value. This function sequentially writes these three bytes to the memory location indicated by slcptr and increments the pointer accordingly. The implementation completely lacks bounds checking. The function does not verify whether slcptr has exceeded the 108-byte boundary of the slcbuf array.

An unauthenticated attacker triggers this vulnerable code path by sending a LINEMODE SLC subnegotiation request with an excessive number of triplets. Because each triplet consumes three bytes, sending more than 36 triplets causes the add_slc function to write past the end of the buffer. The vulnerability constitutes a highly reliable out-of-bounds write primitive.

Both slcbuf and slcptr reside adjacent to each other in the uninitialized data segment (BSS). The sequential overflow sequentially corrupts adjacent variables stored in this memory region. The exact layout of the BSS segment dictates which application state variables an attacker can overwrite, making the exploitation mechanics specific to the target architecture and compiler optimization levels.

Code Analysis

Reviewing the vulnerable C implementation reveals the exact mechanism of the out-of-bounds write primitive. The add_slc function accepts three parameters but lacks any bounds-checking logic. The pointer arithmetic blindly advances slcptr through memory, corrupting adjacent BSS variables.

// Vulnerable Implementation: telnetd/slc.c
static unsigned char slcbuf[108]; // Fixed size
static unsigned char *slcptr;
 
void add_slc(unsigned char func, unsigned char flag, cc_t val) {
    // Vulnerability: No bounds check on slcptr
    if ((*slcptr++ = (unsigned char) func) == 0xff)
        *slcptr++ = 0xff;
    if ((*slcptr++ = (unsigned char) flag) == 0xff)
        *slcptr++ = 0xff;
    if ((*slcptr++ = (unsigned char) val) == 0xff)
        *slcptr++ = 0xff;
}

The necessary remediation introduces a strict bounds check before executing the memory write operations. The modified function calculates the current offset by determining the distance between slcptr and the base address of slcbuf. The function securely discards the input if the remaining buffer space cannot accommodate a new triplet sequence.

// Patched Implementation Concept
void add_slc(unsigned char func, unsigned char flag, cc_t val) {
    // Fix: Ensure slcptr does not exceed slcbuf bounds
    if ((slcptr - slcbuf) >= (sizeof(slcbuf) - 6)) {
        return; // Discard input to prevent overflow
    }
    if ((*slcptr++ = (unsigned char) func) == 0xff)
        *slcptr++ = 0xff;
    if ((*slcptr++ = (unsigned char) flag) == 0xff)
        *slcptr++ = 0xff;
    if ((*slcptr++ = (unsigned char) val) == 0xff)
        *slcptr++ = 0xff;
}

This fix comprehensively eliminates the specific out-of-bounds write vector within add_slc. The architectural design of the Telnet protocol necessitates rigorous bounds checking across all subnegotiation handlers. Software engineers must verify that the process_slc function and related parsing routines accurately enforce the 108-byte constraint during data deserialization.

Exploitation Methodology

Exploitation initiates during the unauthenticated Telnet handshake phase. The attacker establishes a TCP connection to the target daemon and transmits an IAC WILL LINEMODE command. The server acknowledges this request and enters the appropriate state machine phase. This sequence opens the code path required for SLC subnegotiation.

The attacker proceeds by transmitting an IAC SB LINEMODE LM_SLC command followed by a specifically crafted payload of triplet data. The payload contains function codes exceeding the NSLC macro value of 18. This anomalous input forces the process_slc function to generate a "not supported" reply via the vulnerable add_slc routine.

The out-of-bounds write overwrites variables residing in the BSS segment. A critical escalation occurs when the sequential overflow overwrites the slcptr variable itself. The attacker replaces the valid buffer pointer with an arbitrary memory address of their choosing, hijacking the internal state of the daemon.

The server eventually executes the end_slc() function to finalize the network response construction. This function writes the Telnet suboption end marker (IAC SE) directly to the address currently held in the corrupted slcptr. Writing this marker to the attacker-controlled memory address yields a highly reliable, arbitrary memory write primitive.

Impact Assessment

The vulnerability grants an unauthenticated remote attacker complete control over the target system architecture. Exploitation yields arbitrary code execution with the system privileges of the running telnetd process. Because this daemon typically operates as the root user, the attacker achieves total system compromise.

Security researchers documented advanced exploitation techniques effective on specific 32-bit architectures, such as Debian Bookworm i386. The BSS overflow corrupts the def_slcbuf pointer alongside other variables. This specific corruption allows the attacker to trigger an arbitrary free condition, facilitating the bypass of modern exploit mitigations like Address Space Layout Randomization (ASLR).

The vulnerability additionally functions as a reliable information disclosure primitive. Corrupting slcptr to point to internal data structures causes the server to transmit sensitive BSS or heap data back to the attacker within the SLC network response. This memory leak assists the attacker in accurately mapping the target address space prior to final payload execution.

The widespread integration of the GNU Inetutils code base drastically amplifies the operational impact. The vulnerable implementation persists in numerous modern operating systems and legacy embedded devices. Network appliances running legacy services remain highly susceptible to automated exploitation campaigns.

Protocol Flow and Attack Chain

The following diagram illustrates the interaction between the attacker and the vulnerable telnetd service during the exploitation sequence. The chart outlines the specific protocol commands required to trigger the BSS overflow condition.

The sequence highlights the architectural dependency on the LINEMODE protocol feature. The attacker must successfully negotiate this state before transmitting the malicious payload. The final arbitrary write primitive relies on the server finalizing the network response.

Remediation and Mitigation

The most effective remediation strategy requires the complete deprecation of the Telnet protocol across the enterprise environment. Organizations must disable the telnetd service immediately and migrate all remote administration workflows to Secure Shell (SSH). The Telnet protocol transmits all data in plaintext and fundamentally lacks modern cryptographic protections.

Systems strictly requiring Telnet for legacy industrial control systems (ICS) or operational technology (OT) must deploy rigorous network segmentation. Network administrators must implement firewall rules and access control lists (ACLs) to severely restrict access to the Telnet port (TCP/23). Only highly trusted, internal IP addresses should route traffic to the vulnerable service.

Security operations teams must actively monitor network traffic for anomalous Telnet subnegotiation sequences. Intrusion detection systems (IDS) should alert on Telnet packets containing excessively long SLC sequences exceeding 36 triplets. This specific network signature reliably identifies the initial stages of the buffer overflow attack.

Organizations must apply the official GNU Inetutils patches immediately upon their public release. The specific patch modifies the add_slc function to enforce strict bounds checking on the slcbuf array. Administrators should verify the successful application of the patch by scanning internal networks for vulnerable daemon versions using available proof-of-concept detection scripts.

Official Patches

GNUOfficial GNU Inetutils bug tracking and patch discussion.

Technical Appendix

CVSS Score
9.8/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Probability
0.03%
Top 93% most exploited

Affected Systems

GNU Inetutils <= 2.7Debian Linux (Bookworm i386)Ubuntu LinuxopenSUSEFreeBSD (13.x, 15.x ports)NetBSD (10.1)DragonFlyBSDCitrix NetScalerHaikuTrueNAS CoremacOS Tahoe

Affected Versions Detail

Product
Affected Versions
Fixed Version
GNU Inetutils
GNU
<= 2.7TBD
AttributeDetail
CWE IDCWE-120 (Buffer Copy without Checking Size of Input)
Attack VectorNetwork
CVSS Base Score9.8 (Critical)
EPSS Score0.00027
ImpactPre-authentication Remote Code Execution
Exploit StatusWeaponized Proof-of-Concept
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1203Exploitation for Client Execution
Execution
T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

Stack/BSS-based Buffer Overflow

Known Exploits & Detection

GitHub (watchTowr)Detection script to verify vulnerability via minimal overflow.
GitHub (jeffaf)Proof of Concept demonstrating BSS data leak and memory corruption.

Vulnerability Timeline

Vulnerability disclosed to GNU Inetutils maintainers by DREAM Security.
2026-03-11
Public announcement released on Openwall oss-security mailing list.
2026-03-12
CVE-2026-32746 assigned and published.
2026-03-13
Technical analysis and Proof of Concept released by watchTowr Labs.
2026-03-19

References & Sources

  • [1]watchTowr Labs Analysis
  • [2]GNU Inetutils Mailing List
  • [3]oss-security Mailing List Announcement
  • [4]watchTowr PoC
  • [5]jeffaf PoC

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-68585
5.8

CVE-2026-68585: Metadata Disclosure via Missing Authorization in SiYuan API

A metadata disclosure vulnerability exists in SiYuan prior to version v3.7.3. The /api/block/getBlockInfo endpoint fails to validate authorization boundaries in publish mode, allowing anonymous readers to access private document metadata.

Alon Barad
Alon Barad
1 views•8 min read
•about 2 hours ago•CVE-2026-72812
6.5

CVE-2026-72812: Broken Access Control and SQL Injection in SiYuan

A critical authorization bypass vulnerability exists in SiYuan personal knowledge management system before v3.7.4. The /api/ref/refreshBacklink endpoint lacks administrative role verification, enabling unauthenticated users to initiate database transactions and disk operations. When combined with an unsafe SQL generation pattern in nested backlink queries, an attacker can exploit a secondary SQL injection vulnerability to compromise local databases or cause denial-of-service conditions.

Amit Schendel
Amit Schendel
2 views•6 min read
•about 3 hours ago•CVE-2026-72811
10.0

CVE-2026-72811: Remote SQL Injection in SiYuan Backlink and Mention Search Engine

A critical SQL Injection vulnerability exists in the SiYuan note-taking application (versions <= v3.7.2) due to improper neutralization of single quotes within the backlink and mention search queries. Because the application constructs SQLite Full Text Search (FTS) queries via direct string concatenation and uses a database driver that supports stacked query statements, remote unauthenticated attackers can execute arbitrary SQL commands on the master database, compromising all hosted notebooks. This issue has been fully remediated in version v3.7.4.

Amit Schendel
Amit Schendel
3 views•7 min read
•about 4 hours ago•CVE-2026-72810
8.6

CVE-2026-72810: Publish-Boundary Bypass and Real-Time Data Leakage via WebSocket Session Pollution in SiYuan

CVE-2026-72810 is a critical publish-boundary bypass vulnerability in the SiYuan personal knowledge management system before version 3.7.4. The flaw lies in the backend real-time WebSocket broadcast mechanism. When configured in public publish mode, the system fails to differentiate between unauthenticated public reader sessions and authorized administrative sessions within its global connection pool. This architectural oversight allows unauthenticated remote attackers connecting to the public WebSocket endpoint on port 6808 to passively receive real-time, raw workspace modification events, including keystroke logs, block updates, and content from protected or forbidden documents.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 5 hours ago•CVE-2026-72809
8.0

CVE-2026-72809: Authentication Bypass in SiYuan via Localhost Trust Spoofing

An authentication bypass vulnerability exists in the SiYuan personal knowledge management system (versions <= v3.7.2). The flaw occurs because the kernel's authorization validation handler trusts loopback connection origins blindly, allowing remote network attackers to gain administrative privileges via an exposed local reverse proxy.

Alon Barad
Alon Barad
4 views•6 min read
•about 6 hours ago•CVE-2026-72808
6.9

CVE-2026-72808: Unauthorized PDF Annotation Access in SiYuan Knowledge Management System

An information disclosure vulnerability in the SiYuan knowledge management system versions up to and including v3.7.2 allows remote unauthorized attackers to retrieve PDF annotations via the /api/asset/getFileAnnotation endpoint due to missing authorization checks.

Alon Barad
Alon Barad
8 views•6 min read