CVE-2026-6238
Last modified
CVE-2026-6238 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory. These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | >= 2.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-6238?
How severe is CVE-2026-6238?
How do I fix CVE-2026-6238?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6237The Quick Table plugin for WordPress is vulnerable to Stored…6.4
- CVE-2026-62370KubeEdge is an open source system for extending native conta…6.5
- CVE-2026-62371KubeEdge is an open source system for extending native conta…8.8
- CVE-2026-62377libheif is a HEIF and AVIF file format decoder and encoder. …4.3
- CVE-2026-62378RustFS Console is a web management console for the RustFS di…9
- CVE-2026-62379Open Access Management (OpenAM) is an access management solu…9.8
- CVE-2026-62380Netty (io.netty:netty-codec-socks) versions 4.2.0.Final thro…7.5
- CVE-2026-62381luci-lib-px5g (LuCI) contains a heap-based buffer overflow i…6.6
- CVE-2026-62382PasswordPusher versions v1.45.11 through v2.9.5 contain an i…6.9
- CVE-2026-62383nltk versions before 3.10.2 contain a symlink-based arbitrar…5.5
- CVE-2026-62384NLTK versions before 3.10.2 contain a symlink-based sandbox …7.5
- CVE-2026-62385NLTK versions before 3.10.0 contain a path traversal vulnera…7.5
Are you affected by CVE-2026-6238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
