CVE-2026-5358
Wolfi vulnerability analysis and mitigation

Overview

CVE-2026-5358 was initially assigned to a buffer overflow vulnerability in the obsolete nis_local_principal function of the GNU C Library (glibc) version 2.43 and older. The CVE was subsequently rejected on April 22, 2026, for two reasons: (1) no NIS+ client or server was ever released for any Linux-based OS distribution, making the API provisional and unused; and (2) the NIS+ cold start cache (/var/nis/NIS_COLD_START) cannot be bypassed, meaning the API can only be called with a trusted server from the pre-populated cache — no trust boundary is crossed, making this a normal bug rather than a security vulnerability (NVD, Github Advisory). Prior to rejection, CISA-ADP had assigned a CVSS v3.1 score of 9.1 (Critical) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H, which was subsequently removed upon rejection (NVD).

Technical details

The original vulnerability description identified a classic buffer overflow (CWE-120) in the nis_local_principal function within glibc ≤ 2.43. The proposed attack mechanism involved an attacker spoofing a crafted UDP response to a request generated by this function, potentially overwriting neighboring static data in the data section of the requesting application. However, the CVE was rejected because the NIS+ API was never implemented in any Linux distribution and the cold start cache (/var/nis/NIS_COLD_START) prevents untrusted servers from being used, eliminating the attack surface entirely (NVD, Red Hat Bugzilla). NIS support has been deprecated in glibc since version 2.26 and is maintained only for legacy compatibility (Github Advisory).

Impact

Because CVE-2026-5358 has been officially rejected, there is no confirmed security impact. The originally described scenario — a remote attacker overwriting static data via a spoofed UDP response to cause data corruption or denial of service — was determined to be non-exploitable due to the absence of a deployable NIS+ implementation on Linux and the trust enforcement of the cold start cache (NVD, Red Hat Bugzilla).

Exploitability

There is no known public proof-of-concept and no evidence of in-the-wild exploitation. The CVE has been rejected, meaning the vulnerability as originally described does not represent a viable attack path. The EPSS score is approximately 0.018% (0.000180), reflecting an extremely low probability of exploitation (Github Advisory). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Mitigation and workarounds

Since CVE-2026-5358 has been officially rejected and does not represent an exploitable vulnerability, no security patch or urgent remediation is required. Organizations running legacy applications that depend on NIS functionality in glibc should nonetheless consider migrating to modern identity and access management services, as NIS support has been deprecated since glibc 2.26 (NVD, Red Hat Bugzilla). Security teams should update any vulnerability management tooling (e.g., Nessus plugin 308170) to reflect the rejected status of this CVE to avoid false-positive alerts.

Community reactions

Red Hat's Product Security team tracked the issue via Bugzilla (Bug 2459855) and noted the upstream rejection on May 1, 2026, after Carlos O'Donell confirmed the CVE had been marked rejected by the GNU C Library maintainers (Red Hat Bugzilla). Security aggregators including SecurityOnline.info briefly covered the initial disclosure before the rejection was widely propagated. The rejection underscores the importance of thorough pre-publication analysis for CVEs involving legacy or unimplemented APIs.

Additional resources


SourceThis report was generated using AI

Related Wolfi vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72836CRITICAL9.2
  • Wolfi logoWolfi
  • filebrowser
NoYesAug 14, 2026
CVE-2026-72837HIGH8.7
  • Wolfi logoWolfi
  • filebrowser
NoYesAug 14, 2026
CVE-2026-46603HIGH7.5
  • Rclone logoRclone
  • mattermost-11.6
NoYesAug 14, 2026
CVE-2026-72838HIGH7.1
  • Wolfi logoWolfi
  • filebrowser
NoYesAug 14, 2026
CVE-2026-19898LOW2.9
  • Wolfi logoWolfi
  • victoriametrics
NoNoAug 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management