CVE-2026-4438

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
References
Link Resource
https://sourceware.org/bugzilla/show_bug.cgi?id=34015 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

History

07 Apr 2026, 18:40

Type Values Removed Values Added
CPE cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
First Time Gnu
Gnu glibc
References () https://sourceware.org/bugzilla/show_bug.cgi?id=34015 - () https://sourceware.org/bugzilla/show_bug.cgi?id=34015 - Exploit, Issue Tracking, Patch
Summary
  • (es) Llamar a gethostbyaddr o gethostbyaddr_r con un nsswitch.conf configurado que especifica el backend DNS de la biblioteca en la biblioteca GNU C versión 2.34 a la versión 2.43 podría resultar en que se devuelva un nombre de host DNS no válido al llamador en violación de la especificación DNS.

23 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-88

20 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 20:16

Updated : 2026-04-07 18:40


NVD link : CVE-2026-4438

Mitre link : CVE-2026-4438

CVE.ORG link : CVE-2026-4438


JSON object : View

Products Affected

gnu

  • glibc
CWE
CWE-20

Improper Input Validation

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')