libc has multiple security flaws
libc has a CERT-Bund advisory for 2 vulnerabilities. A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 2.34-2.43Fix recorded today
- Affected versions
- affected versions
- Affects
- libc+2 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses.
What to do
Check your libc version. If it is older than 2.34-2.43, this advisory applies.
Update libc to 2.34-2.43 or newer.
Technical details
Affected software: libc, Linux, UNIX
A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses. The advisory tracks CVE-2026-4437, CVE-2026-4438. In CERT-Bund's CSAF data, the fixed version is 2.34-2.43. Affected operating systems listed by CERT-Bund: Linux, UNIX.
References
- wid.cert-bund.de · wid-sec-w-2026-0817.json technical description
- nvd.nist.gov · CVE-2026-4437 third party advisory
- nvd.nist.gov · CVE-2026-4438 third party advisory
- sourceware.org · show_bug.cgi third party advisory
- sourceware.org · show_bug.cgi third party advisory
- lists.suse.com · 025225.html third party advisory
- lists.suse.com · 025211.html third party advisory
- lists.suse.com · 025301.html third party advisory
- lists.suse.com · 025273.html third party advisory
- lists.suse.com · 025351.html third party advisory
- lists.opensuse.org · GFPKIVG6Y3FRW5FU5KIUSL5GMSDW52OV third party advisory
- lists.suse.com · 025528.html third party advisory
- access.redhat.com · RHSA-2026:7316 third party advisory
- security.netapp.com · NTAP-20260410-0017 third party advisory
- access.redhat.com · RHSA-2026:19061 third party advisory
- access.redhat.com · RHSA-2026:20587 third party advisory
- docs.cloud.google.com · release-notes third party advisory
- access.redhat.com · RHSA-2026:20597 third party advisory
- linux.oracle.com · ELSA-2026-20587.html third party advisory
- linux.oracle.com · ELSA-2026-50291.html third party advisory
- errata.build.resf.org · RLSA-2026:20597 third party advisory
- access.redhat.com · RHSA-2026:22634 third party advisory
- access.redhat.com · RHSA-2026:26319 third party advisory
- ibm.com · 7277096 third party advisory
- access.redhat.com · RHSA-2026:28010 third party advisory
- access.redhat.com · RHSA-2026:29197 third party advisory
- linux.oracle.com · ELSA-2026-20597.html third party advisory
- linux.oracle.com · ELSA-2026-33126.html third party advisory
- linux.oracle.com · ELSA-2026-500006.html third party advisory
- ubuntu.com · USN-8611-1 third party advisory
- linux.oracle.com · ELSA-2026-42733.html third party advisory
- linux.oracle.com · ELSA-2026-500065.html third party advisory
- linux.oracle.com · ELSA-2026-500140.html third party advisory
- dell.com · dsa-2026-386-security-update-f third party advisory
- linux.oracle.com · ELSA-2026-500297.html third party advisory