« List of all CVEs

CVE-2026-0915

getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler

Published: 1/15/2026 Last updated: 1/20/2026 Reserved: 1/13/2026

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

CNA assigner: glibc (3ff69d7a-14f2-4f67-a097-88dee7810d18) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.5 High CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Opam packages affected (1)

gettext-stub

Products affected (2)

Product Vendor Version
glibc The GNU C Library 6.6.7
glibc The GNU C Library QCA6698AQ

References (6)

Credits (2)