CVE-2026-4438: GNU Glibc

Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Affected products

  • GNU Glibc: from 2.34, up to and including 2.43

Published 2026-03-20. Last modified 2026-07-14.