USN-8611-1: GNU C Library vulnerabilities

Publication date

27 July 2026

Overview

Several security issues were fixed in GNU C Library.


Packages

Details

It was discovered that the GNU C Library iconv function incorrectly handled
certain IBM character sets. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-4046)

It was discovered that the GNU C Library DNS functions incorrectly handled
certain DNS server responses when using gethostbyaddr or gethostbyaddr_r.
An attacker in a privileged network position could possibly use this issue
to cause an application to violate DNS specification or obtain incorrect
hostname information. This issue only affected Ubuntu 24.04 LTS.
(CVE-2026-4437, CVE-2026-4438)

It was discovered that the GNU C Library deprecated debugging functions
incorrectly enforced caller-supplied buffer lengths. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (

It was discovered that the GNU C Library iconv function incorrectly handled
certain IBM character sets. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-4046)

It was discovered that the GNU C Library DNS functions incorrectly handled
certain DNS server responses when using gethostbyaddr or gethostbyaddr_r.
An attacker in a privileged network position could possibly use this issue
to cause an application to violate DNS specification or obtain incorrect
hostname information. This issue only affected Ubuntu 24.04 LTS.
(CVE-2026-4437, CVE-2026-4438)

It was discovered that the GNU C Library deprecated debugging functions
incorrectly enforced caller-supplied buffer lengths. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2026-5435)

It was discovered that the GNU C Library scanf family of functions
contained a heap buffer overflow when processing certain format specifiers.
An attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-5450)

It was discovered that the GNU C Library ungetwc function incorrectly
handled certain character encodings. An attacker could possibly use this
issue to obtain sensitive information or cause a denial of service.
(CVE-2026-5928)

It was discovered that the GNU C Library deprecated debugging functions
incorrectly validated DNS response record data. An attacker could possibly
use this issue to cause a denial of service or obtain sensitive
information. (CVE-2026-6238)


Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libc6 –  2.43-2ubuntu2.3
24.04 LTS noble libc6 –  2.39-0ubuntu8.8
22.04 LTS jammy libc6 –  2.35-0ubuntu3.14

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›