telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade inetutils | Apr 6, 2026 | Apr 6, 2026 |
| Ubuntu | — | Upgrade inetutils-talk (Ubuntu Pro)Upgrade inetutils-syslogdUpgrade inetutils-ftp (Ubuntu Pro)Upgrade inetutils-ftpdUpgrade inetutils-ping (Ubuntu Pro)Upgrade inetutils-telnetdUpgrade inetutils-ftpUpgrade inetutils-telnetd (Ubuntu Pro)Upgrade telnetUpgrade inetutils-tools (Ubuntu Pro)Upgrade inetutils-talkd (Ubuntu Pro)Upgrade inetutils-tracerouteUpgrade inetutils-talkUpgrade inetutils-pingUpgrade inetutils-talkdUpgrade inetutils-telnet (Ubuntu Pro)Upgrade inetutils-traceroute (Ubuntu Pro)Upgrade inetutils-inetdUpgrade telnetdUpgrade inetutils-telnetUpgrade inetutils-inetd (Ubuntu Pro)Upgrade inetutils-toolsUpgrade inetutils-ftpd (Ubuntu Pro)Upgrade inetutils-syslogd (Ubuntu Pro) | Jun 9, 2026 | Jun 4, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub