PT-2026-26670 · Gnu+1 · Gnu C Library+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU C Library versions 2.34 through 2.43
Description
The GNU C Library contains a flaw where calling the
gethostbyaddr or gethostbyaddr r functions with a specific nsswitch.conf configuration utilizing the library’s DNS backend may lead to a violation of the DNS specification. A crafted response from a configured DNS server could cause the application to incorrectly interpret a non-answer section of the DNS response as a valid answer.Recommendations
Versions prior to 2.34 or after 2.43 should be used.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu C Library
Rocky Linux