CVE-2026-57053

Public on 2026-06-23
Modified on 2026-06-25
Description
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core glibc Pending Fix
Amazon Linux 2 - Core libidn Pending Fix
Amazon Linux 2023 libidn Pending Fix
Amazon Linux 2 - Core libidn2 Not Affected
Amazon Linux 2023 libidn2 Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N