TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2026-4438

MEDIUM
5.4

Beschreibung

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.

CVE Details

CVSS v3.1 Bewertung5.4
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
AngriffsvektorADJACENT_NETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/20/2026
Zuletzt geandert4/7/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

gnu:glibc

Schwachen (CWE)

CWE-20CWE-88

Referenzen

https://sourceware.org/bugzilla/show_bug.cgi?id=34015(3ff69d7a-14f2-4f67-a097-88dee7810d18)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.