{"id":"DEBIAN-CVE-2026-89092","details":"The nscd service in the GNU C Library 2.3.4 onwards may crash due to a  stack overflow when a malicious DNS server returns too large a response  for a DNS query, resulting in degraded DNS resolution for the system.    Exploitation of this bug needs a system that has nscd enabled and using  an untrusted DNS server for name resolution, with the compromised DNS  server being capable of processing records large enough to result in a  stack overflow in an nscd thread stack.  During experimentation, bind 9  was unable to handle large records, but that could change in future or  with a different name server.  In typical installations, nscd is  executed in an isolated context as its own user without a shell, due to  which any compromise of that service is isolated.    There is a remote possibility of nscd cache corruption if an attacker  manages to get the stack pointer into a desired point in the heap,  potentially resulting in other caches in nscd being overwritten with  corrupt data through the stack overflow, until the buggy code path  eventually results in a crash.    Finally, a crash in nscd may result in performance degradation when  resolving names, but it does not result in a denial of service.","modified":"2026-09-12T08:47:29.745868221Z","published":"2026-09-11T02:18:35.460Z","upstream":["CVE-2026-89092"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-89092"}],"affected":[{"package":{"name":"glibc","ecosystem":"Debian:12","purl":"pkg:deb/debian/glibc?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.36-10~0","2.36-9","2.36-9+deb12u1","2.36-9+deb12u10","2.36-9+deb12u11","2.36-9+deb12u12","2.36-9+deb12u13","2.36-9+deb12u14","2.36-9+deb12u2","2.36-9+deb12u3","2.36-9+deb12u4","2.36-9+deb12u5","2.36-9+deb12u6","2.36-9+deb12u7","2.36-9+deb12u8","2.36-9+deb12u9","2.36-9+loong64","2.37-1","2.37-10","2.37-11","2.37-12","2.37-13","2.37-14","2.37-15","2.37-15.1","2.37-15.1+sh4","2.37-15~deb13u1","2.37-16","2.37-17","2.37-18","2.37-19","2.37-2","2.37-3","2.37-4","2.37-5","2.37-6","2.37-7","2.37-8","2.37-9","2.38-1","2.38-10","2.38-11","2.38-12","2.38-12.1","2.38-13","2.38-14","2.38-15~0","2.38-15~1","2.38-2","2.38-3","2.38-4","2.38-5","2.38-6","2.38-7","2.38-7~0+hurd.1","2.38-8","2.38-9","2.39-1","2.39-2","2.39-3","2.39-3.1","2.39-4","2.39-5","2.39-6","2.39-6+hurd.1","2.39-6+sh4","2.39-7","2.39-7+sh4","2.39-7~0","2.39-8~0","2.40-1","2.40-2","2.40-2+sh4","2.40-3","2.40-3+sh4","2.40-4","2.40-5","2.40-5~hurd.1","2.40-6","2.40-6~1","2.40-7","2.41-1","2.41-10","2.41-11","2.41-12","2.41-13~hurd.0","2.41-13~hurd.1","2.41-2","2.41-3","2.41-4","2.41-4~0","2.41-5","2.41-5~0","2.41-6","2.41-7","2.41-8","2.41-8~0","2.41-8~1","2.41-9","2.41-9~0","2.41-9~1","2.42-1","2.42-10","2.42-11","2.42-12","2.42-12~hurd.1","2.42-13","2.42-14","2.42-14~hurd.1","2.42-15","2.42-15~hurd.1","2.42-16","2.42-17","2.42-2","2.42-3","2.42-4","2.42-5","2.42-6","2.42-7","2.42-8","2.42-8~hurd.1","2.42-8~hurd.2","2.42-9","2.43-1","2.43-2","2.43-3","2.43-3+m68k","2.43-4","2.43-4+m68k","2.43-5","2.44-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-89092.json"}},{"package":{"name":"glibc","ecosystem":"Debian:13","purl":"pkg:deb/debian/glibc?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.41-12","2.41-12+deb13u1","2.41-12+deb13u2","2.41-12+deb13u3","2.41-12+deb13u4","2.41-13~hurd.0","2.41-13~hurd.1","2.42-1","2.42-10","2.42-11","2.42-12","2.42-12~hurd.1","2.42-13","2.42-14","2.42-14~hurd.1","2.42-15","2.42-15~hurd.1","2.42-16","2.42-17","2.42-2","2.42-3","2.42-4","2.42-5","2.42-6","2.42-7","2.42-8","2.42-8~hurd.1","2.42-8~hurd.2","2.42-9","2.43-1","2.43-2","2.43-3","2.43-3+m68k","2.43-4","2.43-4+m68k","2.43-5","2.44-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-89092.json"}},{"package":{"name":"glibc","ecosystem":"Debian:14","purl":"pkg:deb/debian/glibc?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.41-12","2.41-13~hurd.0","2.41-13~hurd.1","2.42-1","2.42-10","2.42-11","2.42-12","2.42-12~hurd.1","2.42-13","2.42-14","2.42-14~hurd.1","2.42-15","2.42-15~hurd.1","2.42-16","2.42-17","2.42-2","2.42-3","2.42-4","2.42-5","2.42-6","2.42-7","2.42-8","2.42-8~hurd.1","2.42-8~hurd.2","2.42-9","2.43-1","2.43-2","2.43-3","2.43-3+m68k","2.43-4","2.43-4+m68k","2.43-5","2.44-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-89092.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L"}]}