Description
Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.

The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration. The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion. Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes. Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An assertion failure in glibc’s DNS stub resolver occurs when a search list containing a domain of roughly 200 characters or more is loaded, leading to a process abort. The flaw arises from truncating the search list into a fixed-size buffer and performing a consistency check against the wrong size, causing valid configurations to fail. This results in denial of service for any application that performs name resolution via glibc, including long‑running services that reload /etc/resolv.conf after changes. The weakness is represented by CWE-1025 and CWE-617.

Affected Systems

The GNU C Library glibc versions between 2.26 and 2.44 on Linux distributions are affected. All systems employing these library versions for DNS resolution, such as standard user applications and system daemons that resolve names, are at risk. The criteria for a problem include any glibc 2.26–2.44 compiled with the default resolver, regardless of the operating system vendor.

Risk and Exploitability

The CVSS base score is 5.3, indicating moderate severity, while the EPSS score is below 1 %, showing a very low probability of active exploitation. It is not listed in the CISA KEV catalog. An attacker would need to supply a long search domain via infrastructure elements that write to /etc/resolv.conf—such as DHCP or a VPN server—without elevated privileges. The required attack vector is therefore local network. The impact is a denial of service that terminates the calling process, which could affect critical services.

Generated by OpenCVE AI on September 19, 2026 at 02:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade glibc to version 2.45 or later, which incorporates the bug fix in revision 506ea57086bfb9ce3daff1c14246a1cb532aba0a.
  • As an interim workaround, avoid using search domains approximately 200 characters long; edit /etc/resolv.conf or configure DHCP/VPN servers to supply shorter domains.
  • Restart or reload services that use the glibc resolver after making configuration updates, ensuring the fixed buffer size is not exceeded.

Generated by OpenCVE AI on September 19, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared The Gnu C Library
The Gnu C Library glibc
Vendors & Products The Gnu C Library
The Gnu C Library glibc

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1025
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process. The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration. The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion. Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes. Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software.
Title Assertion failure in the DNS stub resolver with a long search domain
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

The Gnu C Library Glibc
cve-icon MITRE

Status: PUBLISHED

Assigner: glibc

Published:

Updated: 2026-09-17T18:09:16.072Z

Reserved: 2026-05-15T12:15:59.229Z

Link: CVE-2026-8674

cve-icon Vulnrichment

Updated: 2026-09-17T18:09:16.072Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T17:16:53.220

Modified: 2026-09-18T18:17:47.257

Link: CVE-2026-8674

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T16:54:27Z

Links: CVE-2026-8674 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses