The GNU C Library security advisories update for 2026-09-17
GNU C Library advisory describes a DNS stub resolver assertion failure that aborts processes when search domains reach roughly 200 characters in glibc 2.26-2.44.
GLIBC-SA-2026-0021 details an assertion failure in the glibc DNS stub resolver. Systems running glibc versions 2.26 through 2.44 abort when the search list in /etc/resolv.conf or the LOCALDOMAIN environment variable contains a domain of roughly 200 characters or more. The advisory was published as part of the GNU C Library security update batch on 2026-09-17.
- Affects glibc versions 2.26 through 2.44
- Triggered by search domains of roughly 200+ characters in resolv.conf or LOCALDOMAIN
- Impact is process abort (denial of service), not code execution
Posted by Adhemerval Zanella Netto on Sep 17 The following security advisories have been published: GLIBC-SA-2026-0021: =================== Assertion failure in the DNS stub resolver with a long search domain Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process. The...
This source does not provide full text. Read it at seclists.org.