CVE-2026-4438

CVE-2026-4438: gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames

Vendor The Gnu C Library
Product glibc
Weakness CWE-20 · Input validation
Published March 20, 2026
Last update March 23, 2026

CVSS base score

What the vulnerability does

01Description

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

Key dates

02Disclosure timeline

March 20, 2026 CVE published
March 23, 2026 Record updated