#VU124258 Input validation error in GNU C Library (glibc) - CVE-2026-4438
Published: March 23, 2026
GNU C Library (glibc)
GNU
Description
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to insufficient validation when calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library. A remote attacker can force the library to violate the DNS specification and retrieve an invalid DNS hostname to the caller, leading to a potential spoofing attack.