Description
The nscd service in the GNU C Library 2.3.4 onwards may crash due to a
stack overflow when a malicious DNS server returns too large a response
for a DNS query, resulting in degraded DNS resolution for the system.



Exploitation of this bug needs a system that has nscd enabled and using
an untrusted DNS server for name resolution, with the compromised DNS
server being capable of processing records large enough to result in a
stack overflow in an nscd thread stack.  During experimentation, bind 9
was unable to handle large records, but that could change in future or
with a different name server.  In typical installations, nscd is
executed in an isolated context as its own user without a shell, due to
which any compromise of that service is isolated.



There is a remote possibility of nscd cache corruption if an attacker
manages to get the stack pointer into a desired point in the heap,
potentially resulting in other caches in nscd being overwritten with
corrupt data through the stack overflow, until the buggy code path
eventually results in a crash.



Finally, a crash in nscd may result in performance degradation when
resolving names, but it does not result in a denial of service.
Published: 2026-09-11
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: DNS Service Degradation
Action: Monitor
AI Analysis

Impact

A stack overflow occurs in the nscd daemon of the GNU C Library when a DNS query from a malicious DNS server. The overflow corrupts the thread stack, causing nscd to crash or potentially leads to degraded DNS resolution performance but does not provide an attacker with code execution or denial of service capabilities.

Affected Systems

Systems running glibc 2.3.4 or newer with the nscd service enabled and using an untrusted DNS server are affected. The vulnerability only manifests when the DNS server can supply records large enough to exceed the stack allocation used by nscd; typical default installations run nscd as an isolated user, so direct privilege escalation is limited.

Risk and Exploitability

The vulnerability is currently rated with a CVSS score of 4.2, which corresponds to Medium severity. The EPSS score of < 1% indicates a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. Because the crash occurs in a user‑level service and the service runs with limited privileges, the attack surface for privilege escalation is low, but sustained crashes could impair name resolution reliability.

Generated by OpenCVE AI on September 21, 2026 at 04:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade glibc to a version that removes or mitigates the stack allocation flaw in nscd.
  • If nscd is not essential, disable or remove the service to eliminate the attack vector.
  • Configure the system to use a trusted DNS provider or restrict DNS queries so that large, malicious responses cannot be processed by nscd.

Generated by OpenCVE AI on September 21, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared The Gnu C Library
The Gnu C Library glibc
Vendors & Products The Gnu C Library
The Gnu C Library glibc

Fri, 11 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
References

Fri, 11 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name resolution, with the compromised DNS server being capable of processing records large enough to result in a stack overflow in an nscd thread stack.  During experimentation, bind 9 was unable to handle large records, but that could change in future or with a different name server.  In typical installations, nscd is executed in an isolated context as its own user without a shell, due to which any compromise of that service is isolated. There is a remote possibility of nscd cache corruption if an attacker manages to get the stack pointer into a desired point in the heap, potentially resulting in other caches in nscd being overwritten with corrupt data through the stack overflow, until the buggy code path eventually results in a crash. Finally, a crash in nscd may result in performance degradation when resolving names, but it does not result in a denial of service.
Title Stack overflow in nscd due to unbounded alloca use
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

The Gnu C Library Glibc
cve-icon MITRE

Status: PUBLISHED

Assigner: glibc

Published:

Updated: 2026-09-11T17:02:18.288Z

Reserved: 2026-09-10T20:18:09.584Z

Link: CVE-2026-89092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T02:18:35.460

Modified: 2026-09-11T18:17:00.230

Link: CVE-2026-89092

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T01:23:01Z

Links: CVE-2026-89092 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:00:14Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-789

    Memory Allocation with Excessive Size Value