{
  "threat_severity" : "Moderate",
  "public_date" : "2026-04-28T16:43:08Z",
  "bugzilla" : {
    "description" : "glibc: glibc: Application crash or uninitialized memory read via crafted DNS response",
    "id" : "2463539",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2463539"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-1284",
  "details" : [ "The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.\nThese functions are for application debugging only and hence not in the path of code executed by the DNS resolver.  Further, they have been deprecated since version 2.34 and should not be used by any new applications.  Applications should consider porting away from these interfaces since they may be removed in future versions.", "A flaw was found in glibc (GNU C Library). The deprecated functions ns_printrrf, ns_printrr, and fp_nquery do not properly validate the length of RDATA (Resource Record Data) in a DNS (Domain Name System) response when processing specific record types like LOC, CERT, TKEY, or TSIG. A remote attacker could craft a malicious DNS response, leading to a target application crashing or reading uninitialized memory. These functions are intended for application debugging and are not part of the standard DNS resolver path." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42694",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "glibc-0:2.39-128.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42733",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "glibc-0:2.28-251.el8_10.40"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-21T00:00:00Z",
    "advisory" : "RHSA-2026:42733",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "glibc-0:2.28-251.el8_10.40"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-22T00:00:00Z",
    "advisory" : "RHSA-2026:42952",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "glibc-0:2.34-274.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-22T00:00:00Z",
    "advisory" : "RHSA-2026:42952",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "glibc-0:2.34-274.el9_8"
  }, {
    "product_name" : "Red Hat Discovery 2",
    "release_date" : "2026-07-27T00:00:00Z",
    "advisory" : "RHSA-2026:46836",
    "cpe" : "cpe:/a:redhat:discovery:2::el9",
    "package" : "discovery/discovery-server-rhel9:1784821670"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-05-01T00:00:00Z",
    "advisory" : "RHSA-2026:12740",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "glibc-main-2.42-12.hum1"
  }, {
    "product_name" : "Red Hat Insights proxy 1.5",
    "release_date" : "2026-08-11T00:00:00Z",
    "advisory" : "RHSA-2026:53371",
    "cpe" : "cpe:/a:redhat:insights_proxy:1.5::el9",
    "package" : "insights-proxy/insights-proxy-container-rhel9:1786433656"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.10.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44624",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
    "package" : "rhosdt/tempo-gateway-opa-rhel9:1784775772"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.10.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44624",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
    "package" : "rhosdt/tempo-gateway-rhel9:1784775770"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.10.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44624",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
    "package" : "rhosdt/tempo-jaeger-query-rhel9:1784775834"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.10.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44624",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
    "package" : "rhosdt/tempo-operator-bundle:1784777166"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.10.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44624",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
    "package" : "rhosdt/tempo-query-rhel9:1784775793"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.10.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44624",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
    "package" : "rhosdt/tempo-rhel9:1784775768"
  }, {
    "product_name" : "Red Hat OpenShift distributed tracing 3.10.2",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44624",
    "cpe" : "cpe:/a:redhat:openshift_distributed_tracing:3.10::el9",
    "package" : "rhosdt/tempo-rhel9-operator:1784775782"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-rhel9:1784794818"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-rhel9:1784794778"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/haproxy-rhel9:1784795112"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-rhel9:1784794289"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-07-23T00:00:00Z",
    "advisory" : "RHSA-2026:44481",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1784795076"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/cds-kubernetes-tp-rhel9:1787241211"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-tp-rhel9:1787135742"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "compat-glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "compat-glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "glibc",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "openshift/ose-rhel-coreos-9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-6238\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-6238\nhttps://inbox.sourceware.org/libc-announce/7a655d55-276f-41fe-b550-feb3ebb2ce91@redhat.com/T/#u\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34069" ],
  "name" : "CVE-2026-6238",
  "csaw" : false
}