Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://sourceware.org/bugzilla/show_bug.cgi?id=34015 |
|
History
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
The Gnu C Library
The Gnu C Library glibc |
|
| Vendors & Products |
The Gnu C Library
The Gnu C Library glibc |
Fri, 20 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification. | |
| Title | gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames | |
| Weaknesses | CWE-20 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: glibc
Published:
Updated: 2026-03-20T19:59:06.064Z
Reserved: 2026-03-19T19:55:44.639Z
Link: CVE-2026-4438
No data.
Status : Received
Published: 2026-03-20T20:16:49.623
Modified: 2026-03-20T20:16:49.623
Link: CVE-2026-4438
No data.
OpenCVE Enrichment
Updated: 2026-03-23T09:52:53Z
Weaknesses