« List of all CVEs

CVE-2023-4813

Glibc: potential use-after-free in gaih_inet()

Published: 9/12/2023 Last updated: 4/30/2025 Reserved: 9/7/2023

A flaw was found in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.9 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Opam packages affected (1)

gettext-stub

Products affected (12)

Product Vendor Version
Red Hat Enterprise Linux 7 Red Hat <= 1.6.93
Red Hat Enterprise Linux 6 Red Hat < 1908
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat < 10.0.20348.2402
Red Hat Enterprise Linux 9 Red Hat unspecified
Red Hat Enterprise Linux 9 Red Hat 10 Version 1803 for ARM64-based Systems
Red Hat Enterprise Linux 9 Red Hat 389-ds-base 1.4.0.10
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat < 10.0.19045.4291
Red Hat Enterprise Linux 6 Red Hat 7 for 32-bit Systems Service Pack 1
Red Hat Enterprise Linux 8 Red Hat Versions prior to 3.9.10
Red Hat Enterprise Linux 7 Red Hat RT 8.1
Red Hat Enterprise Linux 8 Red Hat <= 0.1.10

References (13)