Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-4438

Опубликовано: 20 мар. 2026
Источник: debian
EPSS Низкий

Описание

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
glibcfixed2.42-14package
glibcfixed2.41-12+deb13u3trixiepackage
glibcfixed2.36-9+deb12u14bookwormpackage
glibcnot-affectedbullseyepackage

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=34015

  • Proposed patch: https://inbox.sourceware.org/libc-alpha/20260320194250.1089143-1-carlos@redhat.com/

  • https://www.openwall.com/lists/oss-security/2026/03/23/2

  • Introduced with: https://sourceware.org/git/?p=glibc.git;a=commit;h=e32547d661a43da63368e488b6cfa9c53b4dcf92 (glibc-2.37)

  • Backported and introduced in glibc-2.36 branch: https://sourceware.org/git/?p=glibc.git;a=commit;h=77f523c473878ec0051582ef15161c6982879095

  • Backported and introduced in glibc-2.34 branch: https://sourceware.org/git/?p=glibc.git;a=commit;h=32e5db37684ffcbc6ae34fcc6cdcf28670506baa

EPSS

Процентиль: 24%
0.00316
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

CVSS3: 4
redhat
4 месяца назад

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

CVSS3: 5.4
nvd
4 месяца назад

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

CVSS3: 5.9
msrc
4 месяца назад

gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames

CVSS3: 5.4
github
4 месяца назад

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

EPSS

Процентиль: 24%
0.00316
Низкий
Уязвимость CVE-2026-4438