[PATCH 2/2] advisories: Reject GLIBC-SA-2026-0008
Florian Weimer
fweimer@redhat.com
Thu Apr 30 15:31:45 GMT 2026
* Florian Weimer:
> * Carlos O'Donell:
>
>> On 4/21/26 3:29 PM, Siddhesh Poyarekar wrote:
>>> On 21/04/2026 13:56, Florian Weimer wrote:
>>>> * Carlos O'Donell:
>>>>
>>>>> On 4/21/26 12:53 PM, Florian Weimer wrote:
>>>>>> * Carlos O'Donell:
>>>>>>
>>>>>>> +NIS+ support in the GNU C Library was never officially supported even
>>>>>>> +though an incomplete implementation of the APIs was made pulibc.
>>>>>>> +Applications should not use any of the NIS+ APIs and should move to
>>>>>>> +modern identity and access management services.
>>>>>>
>>>>>> Maybe also mention that there to the glibc team's knowledge, there are
>>>>>> no server implementations available that this code could interact with?
>>>>>>
>>>>>
>>>>> diff --git a/advisories/GLIBC-SA-2026-0008 b/advisories/GLIBC-SA-2026-0008
>>>>> index 748c0c8944..04b3eeee3e 100644
>>>>> --- a/advisories/GLIBC-SA-2026-0008
>>>>> +++ b/advisories/GLIBC-SA-2026-0008
>>>>> @@ -10,9 +10,11 @@ The use of a trusted server means no trust boundary is crossed and this
>>>>> is therefore considered a normal bug.
>>>>> NIS+ support in the GNU C Library was never officially supported even
>>>>> -though an incomplete implementation of the APIs was made pulibc.
>>>>> -Applications should not use any of the NIS+ APIs and should move to
>>>>> -modern identity and access management services.
>>>>> +though an incomplete implementation of the APIs was made pulibc. To the
>>>>> +best knowledge of the glibc security team no open-source NIS+ server
>>>>> +implementations were ever released for use with this API. Applications
>>>>> +should not use any of the NIS+ APIs and should move to modern identity
>>>>> +and access management services.
>>>>> CVE-Id: CVE-2026-5358
>>>>> Public-Date: 2026-04-10
>>>>> ---
>>>>>
>>>>> Like that?
>>>>
>>>> Yes, it's fine with me. Let's wait a bit what others think.
>>>>
>>> LGTM too.
>>> Reviewed-by: Siddhesh Poyarekar <siddhesh@gotplt.org>
>>>
>>
>> Thanks. Pushed. CVE is now marked as rejected with MITRE.
>
> The rejection did not stick: <https://www.cve.org/CVERecord?id=CVE-2026-5928>
>
> Carlos, would you please take a look?
Looks like the CVE ID was reused here:
<https://sourceware.org/cgit/glibc/tree/advisories/GLIBC-SA-2026-0010>
I don't see an on-list discussion of this change.
Thanks,
Florian
More information about the Libc-alpha
mailing list