PT-2026-95018 · Gnu · Gnu C Library

·

CVE-2026-8674

·

Published

2026-09-17

·

Updated

2026-09-29

CVSS v3.1

5.3

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU C Library versions 2.26 through 2.44
Description Initializing the DNS stub resolver using a LOCALDOMAIN environment variable or an /etc/resolv.conf file containing a search list with a domain of approximately 200 characters or more causes an assertion failure that aborts the process. This occurs because the resolver truncates the search list when copying it into the fixed-size res.defdname buffer, but the subsequent consistency check uses an incorrect size and fails to handle cases where the first entry does not fit. An attacker on the local network could potentially trigger this by providing malicious search domains via DHCP or a VPN server, affecting any process that resolves names through the library.
Recommendations Update GNU C Library to a version later than 2.44.

Exploit

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-101843
CVE-2026-8674
ECHO-00DE-F7D3-2E21
OESA-2026-4016
OPENSUSE-SU-2026:21968-1
RHSA-2026:69276
SUSE-SU-2026:23929-1
SUSE-SU-2026:23934-1
SUSE-SU-2026:23957-1

Affected Products

Gnu C Library