PT-2026-22300 · Gnu · Gnu Inetutils
Ron Ben Yizhak
·
Published
2026-02-27
·
Updated
2026-03-07
·
CVE-2026-28372
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GNU inetutils versions through 2.7
Description
A privilege escalation issue exists in telnetd within GNU inetutils. The issue stems from improper handling of the
CREDENTIALS DIRECTORY environment variable, introduced with systemd service credentials support in the login(1) implementation of util-linux release 2.40. An unprivileged local user can exploit this by creating a login.noauth file.Recommendations
Update to a version of GNU inetutils later than 2.7.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Inetutils