Follow @Openwall on Twitter for new release announcements and other news
[<prev] [<thread-prev] [day] [month] [year] [list]
Message-ID: <9262f36a-a626-44ed-a8b8-af888cc9601b@greenbone.net>
Date: Thu, 22 Jan 2026 11:25:31 +0100
From: Christian Fischer <christian.fischer@...enbone.net>
To: oss-security@...ts.openwall.com
Subject: Re: GNU InetUtils Security Advisory: remote
 authentication by-pass in telnetd

Hello,

On 1/20/26 3:00 PM, Simon Josefsson wrote:
> If someone can allocated a CVE, we will add it in future release notes.

it seems https://www.cve.org/CVERecord?id=CVE-2026-24061 got assigned by 
MITRE to this now:

 > telnetd in GNU Inetutils through 2.7 allows remote authentication 
 > bypass via a "-f root" value for the USER environment variable.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.