{"id":"CVE-2026-89092","title":"glibc: nscd stack overflow leads to degraded DNS resolution (CVE-2026-89092)","summary":"A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, ca…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","cvssSource":"vendor","cwe":["CWE-120","CWE-789"],"vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 6","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","hardened_images","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T21:13:33+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89092.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89092.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89092"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89092"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89092"},{"url":"https://sourceware.org/bugzilla/show_bug.cgi?id=34624"},{"url":"https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00241,"epssPercentile":0.15507,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-11T16:57:22.665457Z"},"ingestedAt":"2026-09-14T00:35:28.536Z","slug":"CVE-2026-89092","body":"## Overview\n\nA flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89092.json)\n\n**glibc: nscd stack overflow leads to degraded DNS resolution** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat Hardened Images\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift Container Platform 4\n- Red Hat Enterprise Linux 9\n- Red Hat Hardened Images\n\nNot affected:\n\n- Red Hat Enterprise Linux 10\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}