CVE-2026-32772: Medium severity GNU InetUtils vulnerability
Published Mar 13, 2026
·Updated
Last updated 8 June 2026
Other sources
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEWENVIRON SEND USERVAR.
— MITRE
Affected Software
3 affected componentsFixes available
GNU InetUtils<=2.7
GNU InetUtils<=2.7
debian/inetutils<=2:2.0-1+deb11u2
2:2.0-1+deb11u42:2.4-2+deb12u32:2.6-3+deb13u32:2.8-2
Event History
Mar 13, 2026
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
DescriptionSeverityWeakness
Mar 16, 2026
Data Sourced
via NVD·02:19 PM
DescriptionSeverityWeaknessAffected Software
Jun 8, 2026
Data Sourced
via Debian·05:04 PM
DescriptionAffected Software
Data Sourced
via Launchpad·05:05 PM
Description
Jun 9, 2026
Data Sourced
via Ubuntu·05:05 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-32772?
CVE-2026-32772 has been classified as a medium severity vulnerability due to the potential for arbitrary environment variable exposure.
2
How do I fix CVE-2026-32772?
To fix CVE-2026-32772, upgrade to GNU inetutils version 2.8 or later, which addresses this vulnerability.
3
What impact does CVE-2026-32772 have on security?
CVE-2026-32772 allows remote attackers to read sensitive environment variables from clients, which may lead to further exploitation.
4
Is CVE-2026-32772 exploitable remotely?
Yes, CVE-2026-32772 is exploitable remotely since it affects the telnet service that can be accessed over a network.
5
What versions of GNU inetutils are affected by CVE-2026-32772?
CVE-2026-32772 affects GNU inetutils versions up to and including 2.7.