https://seclists.org/oss-sec/2026/q3/817: The GNU C Library security advisories update for 2026-09-17

Published Sep 17, 2026
·
Updated

Affected Software

1 affected component
GNU GNU C Library (glibc)>=2.26<=2.44

Frequently Asked Questions

1

Which systems and processes are exposed?

GNU C Library versions 2.26 through 2.44 are affected. Any process that resolves names through the library can abort, including long-running processes that reload /etc/resolv.conf after it changes.

2

What does an attacker need to trigger the failure?

The resolver must be initialized from /etc/resolv.conf or the LOCALDOMAIN environment variable with a search-list domain of roughly 200 characters or more. An attacker on the local network may be able to supply such a search domain through DHCP or a VPN server without privileges on the target, depending on validation performed by the network configuration software.

3

When would a running service encounter the problem after a configuration change?

Long-running processes that reload /etc/resolv.conf can be affected on their next name-resolution query after the file changes. The result is an assertion failure that aborts the process.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203