A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 6.5 | Medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H |
Product | Vendor | Version |
---|---|---|
Red Hat Enterprise Linux 7 | Red Hat | < publication |
Red Hat Enterprise Linux 6 | Red Hat | n/a |
Red Hat Enterprise Linux 9 | Red Hat | Android-5.1.1 |
Red Hat Enterprise Linux 9 | Red Hat | n/a |
Red Hat Enterprise Linux 6 | Red Hat | < 5.2.32 |
Red Hat Enterprise Linux 8 | Red Hat | <24.04.00 |
Red Hat Enterprise Linux 7 | Red Hat | Snapdragon 8 Gen 1 Mobile Platform |
Red Hat Enterprise Linux 8 | Red Hat | All versions < V13.3.0.8 |