CVE-2026-4437Disclosure(gnu / glibc)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-21); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-24: 1Mentions · 2026-03-30: 1Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-09-04: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-24: 103-2103-2403-3009-04
Signal classification3 categories
Disclosure
240.0%
General
240.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure1General1
2026-03-241
Disclosure1
2026-03-301
General1
2026-09-041
PoC1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    2 CVEs in glibc https://www.openwall.com/lists/oss-security/2026/03/23/2 CVE-2026-4437,GLIBC-SA-2026-0005: gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response CVE-2026-4438,GLIBC-SA-2026-0006: gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames

    Post summary

    Openwall announces two new glibc CVEs that impact gethostbyaddr and gethostbyaddr_r, describing incorrect DNS response handling and invalid hostname returns.

    020722.3K
    4.4K followersView on X
  • frances@BPJupiter
    PoC

    recreated CVE-2026-4437 :) https://t.co/aRwl6huVar

    Post summary

    The user indicates they have recreated CVE-2026-4437 and shared a link, but no additional exploitation or patch information is provided.

    10110262
    204 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos GNU ❗ CVE-2026-4437 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-gnu-2/ https://t.co/NWJcUs9NeB

    Post summary

    The tweet simply announces the existence of CVE‑2026‑4437 in GNU products and provides a link for more information without detailing the vulnerability, patches, or exploitation status.

    10010206
    6.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4437 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 coul… https://www.cve.org/CVERecord?id=CVE-2026-4437 ----- Traducción: CVE-2026-4437 Lla… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-4437, provides a brief technical description of the affected glibc functions and versions, and links to the official CVE record. No exploit, mitigation, or active exploitation details are included.

    0000030
    61 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4437 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C Library version 2.34 to version 2.43 coul… https://www.cve.org/CVERecord?id=CVE-2026-4437

    Post summary

    The snippet references CVE-2026-4437 with a brief mention of affected functions and library versions, but it provides no actionable details, proofs of concept, exploitation reports, or patch information.

    00000247
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more