CVE-2026-4438

MEDIUM

gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames

Title source: cna
STIX 2.1

Description

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Scores

CVSS v3 5.4
EPSS 0.0004
EPSS Percentile 13.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-88
Status published
Products (2)
gnu/glibc 2.34 - 2.43
The GNU C Library/glibc 2.34 - 2.43
Published Mar 20, 2026
Tracked Since Mar 21, 2026