CVE-2026-4437 is a high-severity vulnerability in GNU C Library (glibc) versions 2.34 through 2.43. It allows a remote attacker to craft a DNS response that causes applications using gethostbyaddr or gethostbyaddr_r to misinterpret non-answer sections as valid DNS answers. With a CVSS score of 7.5, this vulnerability has a network attack vector and low attack complexity, primarily impacting system availability through potential denial of service. There is currently no evidence of active exploitation, and no public exploit code is available. However, the vulnerability has garnered community attention, with discussions and patches being developed and applied for glibc, indicating active remediation efforts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.34, <= 2.43CPE matchmatch criteria | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.