Bug 2537805 (CVE-2026-95510) - CVE-2026-95510 inetutils: GNU Inetutils uninitialized struct sigaction usage
Summary: CVE-2026-95510 inetutils: GNU Inetutils uninitialized struct sigaction usage
Keywords:
Status: NEW
Alias: CVE-2026-95510
Deadline: 2026-09-25
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-22 10:11 UTC by OSIDB Bzimport
Modified: 2026-09-28 06:26 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-22 10:11:01 UTC
We can see that undef "#ifdef SA_RESTART", sa.sa_flags has its
SA_RESTART bit set without being initialized previously. The concern
Brain raised is that, depending on the contents of the stack,
sa.sa_flags may also have its SA_RESTORER bit set. In addition, the
sa.sa_restorer field would be uninitialized, meaning it would be set to
whatever is on the stack. This field is a function pointer that is used
as a signal trampoline used on some architectures, meaning that it is
used to return from the signal handler back to the code that was
executing at the time the signal was delivered.

I am not very familiar with these signal details, so I asked Adhemerval
Zanella Netto, a glibc maintainer, if he could take a look at the report
to help us better understand the security impact. He mentioned that most
new generic Linux ports are not affected

Ability to reproduce this consistently with custom
setsockopt() implementation by exiting or using CTRL + C in the telnet
session, which triggered SIGCHLD.


Note You need to log in before you can comment on or make changes to this bug.