PT-2026-26671 · Gnu+1 · Gnu C Library+1

CVE-2026-4438

·

Publicado

2026-01-01

·

Atualizado

2026-07-27

CVSS v3.1

5.4

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GNU C library versions 2.34 through 2.43
Description The GNU C library’s gethostbyaddr and gethostbyaddr r functions, when used with a configured nsswitch.conf file specifying the library’s DNS backend, may return invalid DNS hostnames. This behavior violates the DNS specification.
Recommendations Update the GNU C library to a version later than 2.43.

Exploit

Correção

RCE

Argument Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:19061
ALSA-2026:20597
CVE-2026-4438
ECHO-49D5-1F6E-5068
OPENSUSE-SU-2026:10662-1
OPENSUSE-SU-2026:20501-1
RHSA-2026:19061
RHSA-2026:20597
RHSA-2026:7316
SUSE-SU-2026:1369-1
SUSE-SU-2026:20999-1
SUSE-SU-2026:21019-1
SUSE-SU-2026:21039-1
SUSE-SU-2026:21069-1
SUSE-SU-2026:21164-1
USN-8611-1

Produtos afetados

Gnu C Library
Rocky Linux