The GNU C Library disclosed multiple security flaws affecting widely deployed versions of glibc, including two DNS-related bugs in gethostbyaddr and gethostbyaddr_r when the DNS backend is used through nsswitch.conf. Tracked as CVE-2026-4437 and CVE-2026-4438, the issues affect versions 2.34 through 2.43 and stem from defects in the getanswer_ptr function. One flaw can cause glibc to treat a non-answer DNS section as valid and return the wrong hostname, enabling limited reverse-DNS obfuscation for attackers who are network-adjacent or control the DNS server. The other can return invalid DNS hostnames, including names containing shell metacharacters, creating a potential shell-injection path in applications that unsafely pass resolved hostnames to a shell.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-30, the GNU C Library published security advisory GLIBC-SA-2026-0007 describing a denial-of-service vulnerability in iconv() affecting version 2.43 and earlier. The flaw can trigger an assertion failure when converting untrusted input from the IBM1390 or IBM1399 character sets, and glibc noted that removing those character sets is a practical mitigation where they are not needed.
On 2026-03-23, the GNU C Library published two security advisories covering defects in the getanswer_ptr function in glibc 2.34 through 2.43. The advisories said no known DNS server currently returns the malicious responses needed for exploitation and no vulnerable application had been identified for the shell-injection scenario.
The GNU C Library publicly dated two vulnerabilities on 2026-03-20 affecting gethostbyaddr and gethostbyaddr_r when using the DNS backend via nsswitch.conf. CVE-2026-4437 can cause incorrect hostname resolution from malformed DNS responses, and CVE-2026-4438 can return invalid hostnames including shell metacharacters, creating potential shell-injection risk in unsafe applications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.