CVE-2026-6238
Last modified
CVE-2026-6238 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | >= 2.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-6238?
How severe is CVE-2026-6238?
How do I fix CVE-2026-6238?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62355TDengine is an open source, time-series database optimized f…5.4
- CVE-2026-6236The Posts map plugin for WordPress is vulnerable to Stored C…6.4
- CVE-2026-62361listmonk is a standalone, self-hosted, newsletter and mailin…5.5
- CVE-2026-62363ImageMagick is free and open-source software used for editin…5
- CVE-2026-6237The Quick Table plugin for WordPress is vulnerable to Stored…6.4
- CVE-2026-62378RustFS Console is a web management console for the RustFS di…9
- CVE-2026-62386The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-r…8.2
- CVE-2026-62387The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-r…7.1
- CVE-2026-62389Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-6239A stack‑based buffer overflow vulnerability exists in Tapo C…6.8
- CVE-2026-62390Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2026-62391The security fix for CVE-2025-66518 is incomplete. Any clien…8.1
Are you affected by CVE-2026-6238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
