#VU124259 Out-of-bounds read in GNU C Library (glibc) - CVE-2026-4437
Published: March 23, 2026
GNU C Library (glibc)
GNU
Description
The vulnerability allows a remote attacker to perform a spoofing attack.
The vulnerability exists due to a boundary condition when calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version. A remote attacker can send a specially crafted response from the configured DNS server and perform a spoofing attack.