216.73.217.50

CVE-2026-6238

· Published 28/04/2026 19:37 · Modified 28/04/2026 22:16

Labels: CVE-2026-6238 2026-04-283ff69d7a-14f2-4f67-a097-88dee7810d18CVE-2026-6238CWE-126

Essential information

Published
28/04/2026 19:37
Modified
28/04/2026 22:16
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CWE-126
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

CVSS metrics

Description

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

NVD status

Status
Modified — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
nist-nvd-api
NVD
View on NVD

Affected products (CPE)

ProductCPE
gnu / glibc cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

References