[PATCH 2/2] advisories: Reject GLIBC-SA-2026-0008
Florian Weimer
fweimer@redhat.com
Thu Apr 30 15:20:14 GMT 2026
* Carlos O'Donell:
> On 4/21/26 3:29 PM, Siddhesh Poyarekar wrote:
>> On 21/04/2026 13:56, Florian Weimer wrote:
>>> * Carlos O'Donell:
>>>
>>>> On 4/21/26 12:53 PM, Florian Weimer wrote:
>>>>> * Carlos O'Donell:
>>>>>
>>>>>> +NIS+ support in the GNU C Library was never officially supported even
>>>>>> +though an incomplete implementation of the APIs was made pulibc.
>>>>>> +Applications should not use any of the NIS+ APIs and should move to
>>>>>> +modern identity and access management services.
>>>>>
>>>>> Maybe also mention that there to the glibc team's knowledge, there are
>>>>> no server implementations available that this code could interact with?
>>>>>
>>>>
>>>> diff --git a/advisories/GLIBC-SA-2026-0008 b/advisories/GLIBC-SA-2026-0008
>>>> index 748c0c8944..04b3eeee3e 100644
>>>> --- a/advisories/GLIBC-SA-2026-0008
>>>> +++ b/advisories/GLIBC-SA-2026-0008
>>>> @@ -10,9 +10,11 @@ The use of a trusted server means no trust boundary is crossed and this
>>>> is therefore considered a normal bug.
>>>> NIS+ support in the GNU C Library was never officially supported even
>>>> -though an incomplete implementation of the APIs was made pulibc.
>>>> -Applications should not use any of the NIS+ APIs and should move to
>>>> -modern identity and access management services.
>>>> +though an incomplete implementation of the APIs was made pulibc. To the
>>>> +best knowledge of the glibc security team no open-source NIS+ server
>>>> +implementations were ever released for use with this API. Applications
>>>> +should not use any of the NIS+ APIs and should move to modern identity
>>>> +and access management services.
>>>> CVE-Id: CVE-2026-5358
>>>> Public-Date: 2026-04-10
>>>> ---
>>>>
>>>> Like that?
>>>
>>> Yes, it's fine with me. Let's wait a bit what others think.
>>>
>> LGTM too.
>> Reviewed-by: Siddhesh Poyarekar <siddhesh@gotplt.org>
>>
>
> Thanks. Pushed. CVE is now marked as rejected with MITRE.
The rejection did not stick: <https://www.cve.org/CVERecord?id=CVE-2026-5928>
Carlos, would you please take a look?
Thanks,
Florian
More information about the Libc-alpha
mailing list