« List of all CVEs

CVE-2023-4813

Glibc: potential use-after-free in gaih_inet()

Published: 9/12/2023 Last updated: 11/11/2025 Reserved: 9/7/2023

A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.9 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Opam packages affected (1)

gettext-stub

Products affected (17)

Product Vendor Version
Red Hat Enterprise Linux 6 Red Hat Snapdragon 8cx Compute Platform (SC8180XP-AC, AF) "Poipu Pro"
Red Hat Enterprise Linux 7 Red Hat All versions < V2.8
Red Hat Enterprise Linux 7 Red Hat 23.9.0
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 Red Hat before version 3.0.0.6
Red Hat Enterprise Linux 6 Red Hat n/a
Red Hat Enterprise Linux 7 Red Hat <= 0.3.10
Red Hat Enterprise Linux 8 Red Hat n/a
Red Hat Enterprise Linux 8 Red Hat V4.7: All versions < V4.7 HF27
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat n/a
Red Hat Enterprise Linux 9 Red Hat 22.1.11
Red Hat Enterprise Linux 9 Red Hat Snapdragon 820 Automotive Platform
Red Hat Enterprise Linux 9 Red Hat < 6.1.7601.26366
Red Hat Enterprise Linux 9 Red Hat Snapdragon 870 5G Mobile Platform (SM8250-AC)
Red Hat Enterprise Linux 6 Red Hat < 6.3.9600.20821
Red Hat Enterprise Linux 8 Red Hat Snapdragon 710 Mobile Platform
Red Hat Enterprise Linux 8.6 Extended Update Support Red Hat < 2.65.65.65
Red Hat Enterprise Linux 9 Red Hat All versions < V4.8 HF4

References (26)