Re: Security: ftpd vulnerability in GNU inetutils

Simon Josefsson via Bug reports for the GNU Internet utilities <[email protected]> Mon, 13 Apr 2026 09:34:54 +0200
Newsgroups gmane.comp.gnu.inetutils.bugs
Message-ID <[email protected]>
--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

I don't see a lot of reasons to not have details and discussion in
public, most of InetUtils is ancient code and there is surely lots of
problematic things in it (I think we've just seen the beginnings of a
vulnerability report flood here...) -- more public code review and
discussion seems fine to me.  Coordinating analysis and resulting code
fixes with *BSD and other actively maintained implementations would also
be nice.  Alas, I don't have a lot of cycles so will try to focus on
release management so we have a working method to get fixes published.
The v2.8 release is over-due, and I will prioritze getting that out
first.

/Simon

Oculytic <[email protected]> writes:

> Sorry, I did not know the 'bugs' email linked directly to the public list.
> I will email you directly with more details.
>
> On Sun, Apr 12, 2026 at 4:41=E2=80=AFPM Collin Funk <[email protected]=
om> wrote:
>
>> Oculytic <[email protected]> writes:
>>
>> > I've attached a full writeup with root cause analysis, affected code
>> > locations.
>> >
>> > I'd like to propose a 30-day disclosure window from today's date. I'm
>> happy
>> > to work with you on a fix - the writeup includes suggested remediation
>> > approaches (replacing signal/longjmp with a flag-based or self-pipe
>> > approach).
>> >
>> > I also plan to request a CVE ID from MITRE and coordinate with the
>> distros
>> > list once a patch is ready. Please let me know if you'd prefer a
>> different
>> > timeline or process.
>> >
>> > Please confirm receipt when you can.
>>
>> This is a public list [1].
>>
>> Given that the attached writeup looks like it was copy pasted from an
>> LLM, I would appreciate if you could send reproduction steps before I
>> rush to look at it.
>>
>> Collin
>>
>> [1] https://lists.gnu.org/archive/html/bug-inetutils/2026-04/msg00000.ht=
ml
>>

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmncnJ4UHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XQkBQkNZGbwAAoJENc89jjFPAa+BtIA
/iR73CfBurG9y8pASh3cbGOMHpDZfMAtosu6jbpO69GHAP4p7l57d+iVty2VQMsx
+3TCSAvZkpr4P/FuTzZ8JZe8BrgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCZ9F0SgUJDWRmSQCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+wUUBAO64fbZek6FPlRK0DrlWsrjCXuLi6PUxyzCAY6lG2nhUAQC6
qobB9mkZlZ0qihy1x4JRtflqFcqqT9n7iUZkCDIiDbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJn0XTSBQkNZGboAAoJENc89jjF
PAa+0M0BAPPRq73kLnHYNDMniVBOzUdi2XeF32idjEWWfjvyIJUOAP4wZ+ALxIeh
is3Uw2BzGZE6ttXQ2Q+DeCJO3TPpIqaXDAAKCRBRcisI/kdFouzjAQCttteyy4UF
YLFTYg5VMTUi/3JfgJujLvF8pULfi/q0FgEA9OAR8xwLi7TiYPCqfvj/DkKXim43
RrKQbUYuOyEoHAs=
=FFWc
-----END PGP SIGNATURE-----
--=-=-=--