CVE-2026-57053

EUVD-2026-38523
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.41%
Affected Products (NVD)
VendorProductVersion
gnulibidn
0.1.15 ≤
𝑥
< 1.44
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libidn
bookworm
postponed
bullseye
postponed
forky
1.44-1
fixed
sid
1.44-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libidn
bionic
needs-triage
focal
needs-triage
jammy
Fixed 1.38-4ubuntu1.1
released
noble
Fixed 1.42-1ubuntu0.1
released
questing
ignored
resolute
Fixed 1.43-2ubuntu0.26.04.1
released
trusty
needs-triage
xenial
needs-triage