[PATCH 4/5] resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238)

Andreas Schwab schwab@suse.de
Mon Jun 8 12:57:14 GMT 2026


On Apr 30 2026, Florian Weimer wrote:

> @@ -444,6 +445,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen,
>  		char base64_cert[8192], tmp[40];
>  		const char *leader;

There is an odd nested redefinition of tmp here.

-- 
Andreas Schwab, SUSE Labs, schwab@suse.de
GPG Key fingerprint = 0196 BAD8 1CE9 1970 F4BE  1748 E4D4 88E3 0EEA B9D7
"And now for something completely different."


More information about the Libc-alpha mailing list