https://seclists.org/oss-sec/2026/q1/366: Buffer overflow in /bin/su from UNIX v4
Published Mar 21, 2026
·Updated
Affected Software
1 affected component
AT&T su (UNIX v4)=v4
Frequently Asked Questions
1
What is the severity of CVE-2026-xxxx?
The severity of CVE-2026-xxxx is classified as high due to the potential for remote exploitation through buffer overflow.
2
How do I fix CVE-2026-xxxx?
To resolve CVE-2026-xxxx, update to the latest patched version of AT&T su or apply specific security patches provided by the vendor.
3
What systems are affected by CVE-2026-xxxx?
CVE-2026-xxxx affects systems running AT&T su on UNIX v4.
4
What types of attacks can CVE-2026-xxxx facilitate?
CVE-2026-xxxx can facilitate attacks such as privilege escalation and arbitrary code execution due to buffer overflow vulnerabilities.
5
Is there a workaround for CVE-2026-xxxx?
As of now, there is no officially recommended workaround for CVE-2026-xxxx other than applying the patch or updating the software.