32-Year-Old Buffer Overflow Found in GNU Inetutils Telnetd (CVE-2026-32746)
Researchers from the DREAM Security Research Team disclosed a pre-authentication buffer overflow in the LINEMODE SLC negotiation handler of GNU inetutils' Telnet server, a flaw dating back to 1994. Because many vendors' Telnetd implementations, including those in major Linux distributions, derive from the same codebase, the bug's reach extends well beyond a single project.