
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5358 was initially assigned to a buffer overflow vulnerability in the obsolete nis_local_principal function of the GNU C Library (glibc) version 2.43 and older. The CVE was subsequently rejected on April 22, 2026, for two reasons: (1) no NIS+ client or server was ever released for any Linux-based OS distribution, making the API provisional and unused; and (2) the NIS+ cold start cache (/var/nis/NIS_COLD_START) cannot be bypassed, meaning the API can only be called with a trusted server from the pre-populated cache — no trust boundary is crossed, making this a normal bug rather than a security vulnerability (NVD, Github Advisory). Prior to rejection, CISA-ADP had assigned a CVSS v3.1 score of 9.1 (Critical) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H, which was subsequently removed upon rejection (NVD).
The original vulnerability description identified a classic buffer overflow (CWE-120) in the nis_local_principal function within glibc ≤ 2.43. The proposed attack mechanism involved an attacker spoofing a crafted UDP response to a request generated by this function, potentially overwriting neighboring static data in the data section of the requesting application. However, the CVE was rejected because the NIS+ API was never implemented in any Linux distribution and the cold start cache (/var/nis/NIS_COLD_START) prevents untrusted servers from being used, eliminating the attack surface entirely (NVD, Red Hat Bugzilla). NIS support has been deprecated in glibc since version 2.26 and is maintained only for legacy compatibility (Github Advisory).
Because CVE-2026-5358 has been officially rejected, there is no confirmed security impact. The originally described scenario — a remote attacker overwriting static data via a spoofed UDP response to cause data corruption or denial of service — was determined to be non-exploitable due to the absence of a deployable NIS+ implementation on Linux and the trust enforcement of the cold start cache (NVD, Red Hat Bugzilla).
There is no known public proof-of-concept and no evidence of in-the-wild exploitation. The CVE has been rejected, meaning the vulnerability as originally described does not represent a viable attack path. The EPSS score is approximately 0.018% (0.000180), reflecting an extremely low probability of exploitation (Github Advisory). The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Since CVE-2026-5358 has been officially rejected and does not represent an exploitable vulnerability, no security patch or urgent remediation is required. Organizations running legacy applications that depend on NIS functionality in glibc should nonetheless consider migrating to modern identity and access management services, as NIS support has been deprecated since glibc 2.26 (NVD, Red Hat Bugzilla). Security teams should update any vulnerability management tooling (e.g., Nessus plugin 308170) to reflect the rejected status of this CVE to avoid false-positive alerts.
Red Hat's Product Security team tracked the issue via Bugzilla (Bug 2459855) and noted the upstream rejection on May 1, 2026, after Carlos O'Donell confirmed the CVE had been marked rejected by the GNU C Library maintainers (Red Hat Bugzilla). Security aggregators including SecurityOnline.info briefly covered the initial disclosure before the rejection was widely propagated. The rejection underscores the importance of thorough pre-publication analysis for CVEs involving legacy or unimplemented APIs.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."