CVE-2026-6238Patch(gnu / glibc)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu glibc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-126

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • glibc

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-29); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
glibc

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-28: 1Mentions · 2026-04-29: 2Mentions · 2026-07-20: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-07-20: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 2Technical Details · 2026-07-20: 104-2804-2907-20
Signal classification3 categories
Patch
250.0%
General
125.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-281
General1
2026-04-292
Disclosure1Patch1
2026-07-201
Patch1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    2 new glibc security advisories https://www.openwall.com/lists/oss-security/2026/04/28/16 GLIBC-SA-2026-0011,CVE-2026-5435: Potential buffer overflow in ns_sprintrrf TSIG handling path GLIBC-SA-2026-0012,CVE-2026-6238: Buffer overread in ns_printrrf with corrupted RDATA field

    Post summary

    The text announces two new glibc CVEs with technical details about buffer overflow and overread issues, but does not provide PoC, exploit code, or patch information.

    010102549
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    glibc warns of critical flaws (CVE-2026-5435 & CVE-2026-6238) in deprecated DNS functions. Patch legacy apps to avoid buffer overflows and memory leaks. #glibc #LinuxSecurity #InfoSec #CyberSecurity #BufferOverflow #LegacyCode #OpenSource #SysAdmin #Linux https://securityonline.info/glibc-legacy-dns-vulnerability-cve-2026-5435-patch-guide/ https://t.co/fZChUvri8R

    Post summary

    The tweet informs about critical glibc DNS function flaws (CVE‑2026‑5435 & 6238) and urges users to patch legacy applications to mitigate buffer overflow and memory leak risks.

    01044605
    12.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6238 The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in… https://www.cve.org/CVERecord?id=CVE-2026-6238

    Post summary

    The text announces CVE-2026-6238 with brief technical details but no evidence of PoC, patches, or active exploitation.

    00010120
    57.3K followersView on X
  • VulniPulse@vulnipulse
    Patch

    ⚠️ NetApp Active IQ Unified Manager for VMware vSphere alert: CVE-2026-6238 (CVSS 6.5) Attackers could disrupt service or cause a denial of service. Apply the vendor-recommended mitigation. https://vulnipulse.com/advisories/netapp-ntap-20260612-0002 #NetApp #CyberSecurity #CVE

    Post summary

    The post announces a NetApp vulnerability (CVE‑2026‑6238) and urges applying the vendor’s recommended mitigation, providing key details such as CVSS rating and impact.

    0000040
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuglibc---

Explore more