CVE-2026-4438
published 2026-03-20CVE-2026-4438: Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version…
PriorityP422medium5.4CVSS 3.1
AVAACLPRNUINSUCLILAN
EPSS
0.21%
10.7th percentile
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.42-14 (forky) | glibc 2.42-14 (forky) |
| gnu | glibc | >= 0 < 2.42-14 | 2.42-14 |
| gnu | glibc | 2.34 – 2.43 | — |
| msrc | azl3_glibc_2.38-18_on_azure_linux_3.0 | — | — |
| msrc | cbl2_glibc_2.35-10_on_cbl_mariner_2.0 | — | — |
| the_gnu_c_library | glibc | 2.34 – 2.43 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv5.4MEDIUM
vendor_msrc5.9MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-935r-rfch-9mr7: Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch
ghsa_unreviewed·2026-03-20
CVE-2026-4438 [MEDIUM] CWE-20 GHSA-935r-rfch-9mr7: Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
OSV
CVE-2026-4438: Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch
osv·2026-03-20·CVSS 5.4
CVE-2026-4438 [MEDIUM] CVE-2026-4438: Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Red Hat
glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
vendor_redhat·2026-03-20·CVSS 5.4
CVE-2026-4438 [MEDIUM] CWE-838 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
A flaw was found in the GNU C library (glibc). When applications use the `gethostbyaddr` or `gethostbyaddr_r` functions with a `nsswitch.conf` configuration that specifies glibc's DNS backend, the library may return an invalid DNS hostname. This violates the DNS specification and could lead to applications receiving incorrect hostname information, potentially impacting network operations or security decisions.
Statement: This is a LOW impact flaw wh
Microsoft
gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
vendor_msrc·2026-03-10·CVSS 5.9
CVE-2026-4438 [MEDIUM] CWE-20 gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames
Mariner: Mariner
glibc: glibc
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-4438: glibc - Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that sp...
vendor_debian·2026·CVSS 5.4
CVE-2026-4438 [MEDIUM] CVE-2026-4438: glibc - Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that sp...
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.42-14)
sid: resolved (fixed in 2.42-14)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions [fedora-42]
bugzilla·2026-03-23·CVSS 5.4
CVE-2026-4438 [MEDIUM] CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions [fedora-42]
CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Fixed by the following update:
https://bodhi.fedoraproject.org/updates/FEDORA-2026-cd29bb324d
Bugzilla
CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions [fedora-43]
bugzilla·2026-03-23·CVSS 5.4
CVE-2026-4438 [MEDIUM] CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions [fedora-43]
CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Fixed in glibc-2.42-11.fc43
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d13513697d
Bugzilla
CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
bugzilla·2026-03-20·CVSS 5.4
CVE-2026-4438 [MEDIUM] CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
CVE-2026-4438 glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Wiz
CVE-2026-4438 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 10.0
CVE-2026-4438 [CRITICAL] CVE-2026-4438 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4438 :
Wolfi vulnerability analysis and mitigation
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Source : NVD
## 5.4
Score
Published March 20, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Wolfi
Chainguard
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
glibc-langpack-ia
glibc-langpack-rif
Sources
NVD
Chainguard Has Fix Added at: Mar 21, 2026
Debian 11, 12, 13
2026-03-20
Published