A 32-year-old pre-authentication buffer overflow vulnerability (CVE-2026-32746) in Telnetd was recently discovered by the DREAM Security Research Team. The BSS-based buffer overflow in the LINEMODE SLC negotiation handler affects GNU inetutils and many vendor implementations across major Linux distributions, FreeBSD, NetBSD, and other systems, allowing attackers to corrupt adjacent memory.
A security researcher disclosed multiple vulnerabilities in GPG discovered in 2025, including signature spoofing and memory corruption bugs. While some issues were patched, others remained unaddressed despite advance notice, prompting a detailed talk at 39c3 examining the vulnerabilities, GnuPG's response, and broader implications for responsible disclosure and security.