PT-2026-26671 · Gnu · Gnu C Library

Published

2026-01-01

·

Updated

2026-03-24

·

CVE-2026-4438

CVSS v3.1

5.4

Medium

AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GNU C library versions 2.34 through 2.43
Description The GNU C library’s gethostbyaddr and gethostbyaddr r functions, when used with a configured nsswitch.conf file specifying the library’s DNS backend, may return invalid DNS hostnames. This behavior violates the DNS specification.
Recommendations Update the GNU C library to a version later than 2.43.

Fix

RCE

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4438

Affected Products

Gnu C Library