libc has multiple security flaws

Published September 11, 2026

libc has a CERT-Bund advisory for 2 vulnerabilities. A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses.

Severity
Not scoredNo CVSS score recorded
Fix
Fixed in 2.34-2.43Fix recorded today
Affected versions
affected versions
Affects
libc+2 more
Exploited
Not confirmedNo confirmation recorded

How it works

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses.

What to do

Check your libc version. If it is older than 2.34-2.43, this advisory applies.

Update libc to 2.34-2.43 or newer.

Technical details

Affected software: libc, Linux, UNIX

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses. The advisory tracks CVE-2026-4437, CVE-2026-4438. In CERT-Bund's CSAF data, the fixed version is 2.34-2.43. Affected operating systems listed by CERT-Bund: Linux, UNIX.

References