These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-6238 is a vulnerability in the GNU C Library's deprecated functions ns_printrrf, ns_printrr, and fp_nquery. These functions, used for application debugging, fail to validate RDATA content against the RDATA length in DNS responses for A6, CERT, LOC, TKEY, or TSIG records. This oversight may allow an attacker to craft a malicious DNS response, potentially causing a target application to crash or re [truncated]
The GNU C Library versions 2.2 and newer contain a vulnerability due to the deprecated functions ns_printrrf, ns_printrr, and fp_nquery failing to enforce the caller-supplied buffer length. This can result in an out-of-bounds write when printing TSIG records. The vulnerability has a CVSS score of 7.3 and is classified as HIGH. Affected product deployments should be identified, and owners assigned for foll [truncated]
CVE-2026-5928 is a HIGH severity vulnerability in the GNU C Library version 2.43 or earlier. The ungetwc function may result in an attempt to read bytes before an allocated buffer, potentially leading to unintentional disclosure of neighboring data in the heap or a program crash. This vulnerability affects systems using the GNU C Library, particularly those with specific character encoding configurations. [truncated]
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when converting inputs from the IBM1390 or IBM1399 character sets. This vulnerability can be trivially mitigated by removing the IBM1390 and IBM1399 character sets from systems that do not need them. Affected systems may experience crashes or instability. Users should verify the presence of these char [truncated]
A vulnerability was found in the GNU C library version 2.34 to version 2.43. Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification. This issue arises from the library's handling of DNS responses. The vulnerability has a CVSS score of 5.4 and [truncated]
The GNU C Library (glibc) versions 2.34 to 2.43 are vulnerable to a HIGH severity issue, CVE-2026-4437, which could allow an attacker to cause an application to treat a non-answer section of a DNS response as a valid answer. This issue occurs when using the gethostbyaddr or gethostbyaddr_r functions with a crafted response from a configured DNS server. The vulnerability has a CVSS score of 7.5 and is cons [truncated]