PT-2026-35750 · Gnu · Gnu C Library

Published

2026-04-28

·

Updated

2026-05-04

·

CVE-2026-6238

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions GNU C Library versions 2.2 through 2.33 GNU C Library version 2.34 (affected versions not specified)
Description The deprecated functions ns printrrf(), ns printrr(), and fp nquery() fail to validate RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY, or TSIG records. This lack of validation may allow an attacker to craft a DNS response that causes a target application to crash or read uninitialized memory. These functions are intended for application debugging and are not in the execution path of the DNS resolver.
Recommendations Stop using the functions ns printrrf(), ns printrr(), and fp nquery() and port applications away from these interfaces as they are deprecated and may be removed in future versions.

Fix

Buffer Over-read

Weakness Enumeration

Related Identifiers

CVE-2026-6238
ECHO-916F-8705-1B52
RHSA-2026:12740

Affected Products

Gnu C Library