Bug 2537805 (CVE-2026-95510)

Summary: CVE-2026-95510 inetutils: GNU Inetutils uninitialized struct sigaction usage
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in inetutils. The application fails to properly initialize signal-handling structures before use. A local user could exploit this vulnerability by triggering specific signal events, potentially leading to arbitrary code execution or an application crash resulting in a Denial of Service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-09-25   

Description OSIDB Bzimport 2026-09-22 10:11:01 UTC
We can see that undef "#ifdef SA_RESTART", sa.sa_flags has its
SA_RESTART bit set without being initialized previously. The concern
Brain raised is that, depending on the contents of the stack,
sa.sa_flags may also have its SA_RESTORER bit set. In addition, the
sa.sa_restorer field would be uninitialized, meaning it would be set to
whatever is on the stack. This field is a function pointer that is used
as a signal trampoline used on some architectures, meaning that it is
used to return from the signal handler back to the code that was
executing at the time the signal was delivered.

I am not very familiar with these signal details, so I asked Adhemerval
Zanella Netto, a glibc maintainer, if he could take a look at the report
to help us better understand the security impact. He mentioned that most
new generic Linux ports are not affected

Ability to reproduce this consistently with custom
setsockopt() implementation by exiting or using CTRL + C in the telnet
session, which triggered SIGCHLD.