Microsoft Security Response Center guidance
CBL-Mariner Releases
Vendor-listed releases
- 2.38-19
Vulnerability intelligence
CVE-2026-4438 and is rated Medium severity with a CVSS score of 5.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.