Re: Security: ftpd vulnerability in GNU inetutils

Oculytic <[email protected]> Sun, 12 Apr 2026 18:48:10 +0100
Newsgroups gmane.comp.gnu.inetutils.bugs
Message-ID <CAJfnK9MGaaWDjLzdgOujsmd0wL8FfRu2rWCLOrNnBgg2qo_k7Q@mail.gmail.com>
--000000000000df8d61064f46f8ff
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Sorry, I did not know the 'bugs' email linked directly to the public list.
I will email you directly with more details.

On Sun, Apr 12, 2026 at 4:41=E2=80=AFPM Collin Funk <[email protected]=
> wrote:

> Oculytic <[email protected]> writes:
>
> > I've attached a full writeup with root cause analysis, affected code
> > locations.
> >
> > I'd like to propose a 30-day disclosure window from today's date. I'm
> happy
> > to work with you on a fix - the writeup includes suggested remediation
> > approaches (replacing signal/longjmp with a flag-based or self-pipe
> > approach).
> >
> > I also plan to request a CVE ID from MITRE and coordinate with the
> distros
> > list once a patch is ready. Please let me know if you'd prefer a
> different
> > timeline or process.
> >
> > Please confirm receipt when you can.
>
> This is a public list [1].
>
> Given that the attached writeup looks like it was copy pasted from an
> LLM, I would appreciate if you could send reproduction steps before I
> rush to look at it.
>
> Collin
>
> [1] https://lists.gnu.org/archive/html/bug-inetutils/2026-04/msg00000.htm=
l
>

--000000000000df8d61064f46f8ff
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Sorry, I did not know the &#39;bugs&#39; email linked dire=
ctly to the public list. I will email you directly with more details.</div>=
<br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=
=3D"gmail_attr">On Sun, Apr 12, 2026 at 4:41=E2=80=AFPM Collin Funk &lt;<a =
href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote=
:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.=
8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Oculytic &lt;<=
a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</=
a>&gt; writes:<br>
<br>
&gt; I&#39;ve attached a full writeup with root cause analysis, affected co=
de<br>
&gt; locations.<br>
&gt;<br>
&gt; I&#39;d like to propose a 30-day disclosure window from today&#39;s da=
te. I&#39;m happy<br>
&gt; to work with you on a fix - the writeup includes suggested remediation=
<br>
&gt; approaches (replacing signal/longjmp with a flag-based or self-pipe<br=
>
&gt; approach).<br>
&gt;<br>
&gt; I also plan to request a CVE ID from MITRE and coordinate with the dis=
tros<br>
&gt; list once a patch is ready. Please let me know if you&#39;d prefer a d=
ifferent<br>
&gt; timeline or process.<br>
&gt;<br>
&gt; Please confirm receipt when you can.<br>
<br>
This is a public list [1].<br>
<br>
Given that the attached writeup looks like it was copy pasted from an<br>
LLM, I would appreciate if you could send reproduction steps before I<br>
rush to look at it.<br>
<br>
Collin<br>
<br>
[1] <a href=3D"https://lists.gnu.org/archive/html/bug-inetutils/2026-04/msg=
00000.html" rel=3D"noreferrer" target=3D"_blank">https://lists.gnu.org/arch=
ive/html/bug-inetutils/2026-04/msg00000.html</a><br>
</blockquote></div>

--000000000000df8d61064f46f8ff--