CVE-2026-6238
published 2026-04-28CVE-2026-6238: The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUINSUCLINAL
EPSS
0.36%
28.2th percentile
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.
These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | glibc | >= 2.2 | — |
| the_gnu_c_library | glibc | 2.0.1 – 2.43 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h8wx-jcwq-g3cp: The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2
ghsa_unreviewed·2026-04-28
CVE-2026-6238 [MEDIUM] CWE-126 GHSA-h8wx-jcwq-g3cp: The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.
These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.
VulDB
GNU C Library up to 2.33 DNS Response ns_printrrf/ns_printrr/fp_nquery buffer over-read
vuldb·2026-04-28·CVSS 6.5
CVE-2026-6238 [MEDIUM] GNU C Library up to 2.33 DNS Response ns_printrrf/ns_printrr/fp_nquery buffer over-read
A vulnerability classified as problematic has been found in GNU C Library up to 2.33. This impacts the function ns_printrrf/ns_printrr/fp_nquery of the component DNS Response Handler. This manipulation causes buffer over-read.
This vulnerability is registered as CVE-2026-6238. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
Red Hat
glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
vendor_redhat·2026-04-28·CVSS 6.5
CVE-2026-6238 [MEDIUM] CWE-1284 glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path.
Package: glibc (Red Hat Enterprise Linux 10) - Not affected
Package: compat-glibc (Red Hat Enterprise Linux 6) - Not affected
Package: glibc (Red Hat Enterprise Linux 6) - Not affected
Pack
No detection rules found.
No public exploits indexed.
2026-04-28
Published