Critical Out-of-Bounds Vulnerability in GNU Libidn Affects Fedora Systems

Critical Out-of-Bounds Vulnerability in GNU Libidn Affects Fedora Systems

First seen 12 Aug 2026, 02:41 UTC Linuxsecurity 85% similarity 72.8

Article Content

Browse articles
ThreatCluster

A critical out-of-bounds vulnerability, CVE-2026-57053, has been identified in the GNU Libidn library, which is used in Fedora systems for internationalized domain names. The vulnerability allows for out-of-bounds reads in the ToUnicode APIs, potentially leading to information disclosure. Affected versions include libidn 1.43-3 and earlier, with updates released on June 22, 2026, for Fedora 43 and June 23, 2026, for mingw-libidn. Users are advised to audit their Linux privileges to prevent escalation and system-wide damage. The vulnerability was published on June 23, 2026, and is being addressed through security updates. Administrators can apply the updates using the 'dnf' package manager. The current status indicates that the vulnerability is critical, and immediate action is recommended.

Key Points: • CVE-2026-57053 is a critical out-of-bounds vulnerability in GNU Libidn. • The vulnerability affects Fedora systems and allows for potential information disclosure. • Users are urged to apply security updates and review Linux privileges to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-06-22
Fedora 43 libidn update released
An update to version 1.44-1 was released to address CVE-2026-57053 for Fedora 43.
Article 1
2026-06-23
CVE-2026-57053 published
A critical out-of-bounds vulnerability in GNU Libidn was disclosed, affecting multiple Fedora versions.
Article 1
2026-06-23
Fedora mingw-libidn update released
An update to version 1.44-1 was released to address CVE-2026-57053 for mingw-libidn.
Article 2
2026-08-12
Security advisory issued for Fedora 44 libidn
A security advisory was published for Fedora 44 addressing the same CVE-2026-57053 vulnerability.
Article 3

Community

Browse all →

Tracked Entities in This Story