PT-2026-3138 · Unknown+4 · Gnu C Library+4

Igor Morgenstern

·

Published

2026-01-15

·

Updated

2026-05-05

·

CVE-2026-0915

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNU C Library versions 2.0 through 2.42
Description The GNU C Library contains a flaw where calling getnetbyaddr or getnetbyaddr r with a configured nsswitch.conf that specifies the library's DNS backend for networks, and querying for a zero-valued network, can lead to the disclosure of stack contents to the configured DNS resolver. This can potentially bypass Address Space Layout Randomization (ASLR), leak credentials, expose cryptographic keys, and facilitate the exploitation of other memory corruption flaws. The issue stems from insufficient validation in the glibc DNS resolution functions, causing uninitialized stack memory to be transmitted to DNS resolvers. The functions getnetbyaddr() and getnetbyaddr r() are implicated in this information exposure.
Recommendations Update to glibc version 2.43 or later when available via distribution security updates. Modify /etc/nsswitch.conf to remove DNS from network resolution (networks: files). Audit DNS traffic for anomalous queries and review applications invoking network resolution functions with zero parameters.

Exploit

Fix

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

ALSA-2026:1334
ALSA-2026:2786
ALSA-2026:4772
AZL-74633
AZL-74817
BDU:2026-02104
CVE-2026-0915
ECHO-5E35-7ADB-017F
MGASA-2026-0022
OESA-2026-1198
OESA-2026-1199
OESA-2026-1200
OESA-2026-1201
OESA-2026-1202
OESA-2026-1266
OPENSUSE-SU-2026:10662-1
OPENSUSE-SU-2026:20133-1
RHSA-2026:1334
RHSA-2026:2786
RHSA-2026:4772
RHSA-2026:7316
SUSE-SU-2026:0371-1
SUSE-SU-2026:0680-1
SUSE-SU-2026:0896-1
SUSE-SU-2026:20178-1
SUSE-SU-2026:20198-1
SUSE-SU-2026:20527-1
SUSE-SU-2026:20536-1
USN-8005-1

Affected Products

Gnu C Library
Linuxmint
Red Os
Rocky Linux
Ubuntu