Skip to main content
EPSS 0.1%top 96%

Security update for libidn

0
Medium
Published: 09/04/2026 (09/04/2026, 07:32:32 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for libidn fixes the following issue: - CVE-2026-57053: out-of-bounds read in `ToUnicode` APIs (bsc#1268965).

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64libidn2-main@aarch64SUSElibidn-devel-1.43-160000.3.1.aarch64libidn-tools-1.43-160000.3.1.aarch64libidn12-1.43-160000.3.1.aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:44:54 UTC

Technical Analysis

CVE-2026-57053 is a medium severity vulnerability in GNU libidn's idna_to_unicode_internal() function, which mishandles the ToUnicode APIs by assuming the internal buffer always starts with the "xn--" ACE prefix. When decoding pure ASCII labels shorter than four characters, no prefix is added, causing the function to read past the buffer's null terminator into uninitialized stack memory. This out-of-bounds read can lead to silent acceptance and normalization of invalid ACE-encoded labels, potentially affecting domain-based security decisions such as allow/deny-list matching, hostname comparisons, routing, and logging. The flaw does not impact libidn2, which properly guards against this condition. The vulnerability is tracked under CWE-125 (Out-of-bounds Read).

Potential Impact

The vulnerability can cause information disclosure by reading uninitialized stack memory, which may include sensitive data such as cryptographic keys or memory addresses. It can also lead to denial of service through application crashes caused by out-of-bounds memory reads. Additionally, the flaw may allow bypassing domain-based security mechanisms by normalizing invalid domain labels to different strings, potentially impacting security decisions in applications relying on these APIs.

Mitigation Recommendations

No configuration-level mitigation is available because the vulnerability depends on uninitialized stack content, making behavior non-deterministic and input filtering ineffective. Users should update to a fixed version of the libidn package once it is released. Until a fix is available, applications processing untrusted internationalized domain names should treat the output of idna_to_unicode_8z8z()/idna_to_unicode_8zlz() as unverified, perform independent comparisons against the original ACE-encoded input, or switch to using libidn2 for IDNA processing, which is not affected by this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:42125
Cve Count
1
State
PUBLISHED

Threat ID: 6a6daacfbf32cb7a3466722f

Added to database: 08/01/2026, 08:14:07 UTC

Last enriched: 08/16/2026, 17:44:54 UTC

Last updated: 09/17/2026, 02:02:22 UTC

Views: 30

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses