A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
2023-09-12T22:15:08.277
2025-04-30T20:15:20.147
Modified
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | glibc | < 2.36 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |
Operating System | redhat | enterprise_linux | 9.0 | Yes |
Operating System | redhat | enterprise_linux_eus | 8.8 | Yes |
Operating System | redhat | enterprise_linux_eus | 9.2 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems_eus_s390x | 9.2 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems_s390x | 9.2 | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian | 9.2_ppc64le | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian_eus | 9.2_ppc64le | Yes |
Operating System | redhat | enterprise_linux_server_aus | 9.2 | Yes |
Operating System | redhat | enterprise_linux_server_tus | 8.8 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h300s | - | No |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Operating System | netapp | h410c_firmware | - | Yes |
Hardware | netapp | h410c | - | No |