- Sources: glibc 2.44 announcement, Phoronix
- Summary: Andreas K. Huettel announced glibc 2.44 on 2026-07-25. System-wide tunables can now be applied from
/etc/tunables.conf plus an ldconfig run, though the file format and path are stated as not part of the stable interface. A new glibc.elf.thp tunable maps read-only segments with transparent huge pages, and the THP page size in malloc is capped at MAX_THP_PAGESIZE. Correctly rounded cosh, sinh, and tanh were imported from the CORE-MATH project, AArch64 gains vectorized SVE and AdvSIMD special cases plus locking of Guarded Control Stack operations after GCS is enabled, RISC-V gains vector-extension string and memory routines, and LoongArch32 is now supported. The security section of the announcement names three CVEs: CVE-2026-4437 and CVE-2026-4438, both in gethostbyaddr and gethostbyaddr_r DNS response handling, and CVE-2026-4046, an iconv assertion failure on untrusted input. A fourth, CVE-2026-6238, appears only in the resolved-bug list, as bug 34069, a buffer overread in ns_sprintrrf on a corrupted RDATA field. Related bug 34033, ns_sprintrrf overflowing a caller buffer on the TSIG path, is fixed in the same release with no CVE assigned. The announcement names the fixed version only, so the affected version ranges are not yet known here. Compatibility changes drop the 31-bit s390-linux-gnu configuration and remove the --enable-memory-tagging and --enable-static-nss configure options. - Why it matters: glibc is the C library under nearly every Linux deployment, so the
iconv crash on untrusted input and the gethostbyaddr and ns_sprintrrf fixes reach any process that converts encodings or resolves addresses. - Follow-up: Watch for the affected version ranges of the four CVEs, for distribution rollouts, and for whether the memory-tagging removal affects AArch64 hardening work downstream.
send feedback on this story