CVE-2026-4438: GNU Glibc
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Affected products
- GNU Glibc: from 2.34, up to and including 2.43
Published 2026-03-20. Last modified 2026-07-14.