The GNU C Library project disclosed two security flaws in gethostbyaddr() and gethostbyaddr_r() affecting glibc versions 2.34 through 2.43 when the DNS backend is enabled through nsswitch.conf, and shipped fixes in glibc 2.44. According to the published advisories, CVE-2026-4437 can cause crafted DNS replies to treat non-answer sections as valid answers, potentially returning an incorrect hostname and enabling limited reverse-DNS obfuscation, while CVE-2026-4438 may accept invalid DNS hostnames containing shell metacharacters, creating a potential shell-injection risk if an application later passes the hostname to a shell unsafely.
The maintainers said exploitation would require a network-adjacent attacker or a compromised DNS server, and noted that no affected DNS servers or vulnerable applications were known at the time of disclosure. Release notes for glibc 2.44 also tie the update to a third security fix, CVE-2026-4046, in iconv() handling of the IBM1390 and IBM1399 character sets, where malformed conversions could trigger incorrect processing or memory corruption under specific conditions.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The GNU C Library 2.44 release announcement said the release also resolved additional security-relevant bugs beyond the three previously highlighted CVEs, including CVE-2026-6238 in ns_sprintrrf plus stack overflow, heap overflow, pointer guard, stack canary, and invalid free issues. This expanded the publicly disclosed security impact of the 2.44 release.
An oss-security post announced two new GNU C Library security advisories covering glibc 2.34 through 2.43 when the DNS backend is used. The flaws affect gethostbyaddr and gethostbyaddr_r, enabling hostname confusion and potential shell-injection risk under specific conditions.
The release of GNU C Library 2.44 included security fixes for CVE-2026-4437, CVE-2026-4438, and CVE-2026-4046 alongside new functionality and architecture support. The fixed issues included the gethostbyaddr/gethostbyaddr_r flaws and an iconv() issue affecting IBM1390 and IBM1399 conversions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
savannah.gnu.org
Open sourceseclists.org
Open sourcesecurity-tracker.debian.org
Open sourcesecurity-tracker.debian.org
Open sourceopenwall.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourcesourceware.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.