* GNU Libidn Security Advisory: Read out of bounds in ToUnicode APIs The Libidn ToUnicode API family (idna_to_unicode*) will read out of bounds for some input strings.
Report with analysis, reproducer and a suggested solution: https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html ** Severity and Vulnerable versions Severity: Low Affected are GNU Libidn since at least version 0.1.15 from 2003-06-07 up to and including version 1.43 released on 2025-03-21. ** Recommendation - Upgrade to Libidn version 1.44 or later. - Apply the patch to your older Libidn release. ** Patch The solution was suggested in the initial report: https://codeberg.org/libidn/libidn/commit/f57fab06afc1e328bbe197ad3d4a4e83c829593e ** Credits Reported by DMSAN (Differential Memory Sanitizer) on 2026-05-19 including analysis, proof of concept and suggested fix. GNU Libidn 1.44 including the fix was released on 2026-06-16. This advisory was drafted by Simon Josefsson on 2026-06-16.
signature.asc
Description: PGP signature
