PT-2026-35750 · Gnu+4 · Gnu C Library+4

CVE-2026-6238

·

Published

2026-04-28

·

Updated

2026-08-25

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions GNU C Library versions 2.2 through 2.33 GNU C Library version 2.34 (affected versions not specified)
Description The deprecated functions ns printrrf(), ns printrr(), and fp nquery() fail to validate RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY, or TSIG records. This lack of validation may allow an attacker to craft a DNS response that causes a target application to crash or read uninitialized memory. These functions are intended for application debugging and are not in the execution path of the DNS resolver.
Recommendations Stop using the functions ns printrrf(), ns printrr(), and fp nquery() and port applications away from these interfaces as they are deprecated and may be removed in future versions.

Fix

DoS

Buffer Over-read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:42694
ALSA-2026:42733
ALSA-2026:42952
AZL-85004
BDU:2026-10480
CVE-2026-6238
ECHO-916F-8705-1B52
OESA-2026-2592
OESA-2026-2593
OESA-2026-2594
OESA-2026-2767
OPENSUSE-SU-2026:11140-1
OPENSUSE-SU-2026:21228-1
RHSA-2026:12740
RHSA-2026:42694
RHSA-2026:42733
RHSA-2026:42952
SUSE-SU-2026:22453-1
SUSE-SU-2026:22523-1
SUSE-SU-2026:22538-1
SUSE-SU-2026:2987-1
SUSE-SU-2026:3029-1
SUSE-SU-2026:3030-1
USN-8611-1

Affected Products

Gnu C Library
Linuxmint
Red Os
Rocky Linux
Ubuntu