PT-2023-8453 · Glibc+8 · Glibc+8

Guilherme De Almeida Suckevicz

+1

·

Published

2023-09-12

·

Updated

2026-05-12

·

CVE-2023-4806

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions glibc (affected versions not specified)
Description A flaw was found in glibc, where the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the nss * gethostbyname2 r and nss * getcanonname r hooks without implementing the nss * gethostbyname3 r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF INET6 address family with AI CANONNAME, AI ALL, and AI V4MAPPED as flags.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2023:5453
ALSA-2023:5455
AZL-29954
AZL-34738
BDU:2024-00852
CESA-2023_5455
CVE-2023-4806
DSA-5514-1
MGASA-2023-0270
OESA-2023-1688
OPENSUSE-SU-2024:13273-1
RHSA-2023:5453
RHSA-2023:5455
RHSA-2023:7409
RHSA-2023_5453
RHSA-2023_5455
RLSA-2023:5455
ROSA-SA-2025-2637
USN-6541-1
USN-6541-2

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Red Hat
Rocky Linux
Ubuntu
Glibc