Описание
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| lunar | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| trusty | ignored  | end of standard support | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | ignored  | end of standard support | 
| devel | released  | 2.38-1ubuntu5 | 
| esm-infra/bionic | not-affected  | code not present | 
| esm-infra/focal | not-affected  | code not present | 
| esm-infra/xenial | not-affected  | code not present | 
| focal | not-affected  | code not present | 
| jammy | not-affected  | code not present | 
| lunar | released  | 2.37-0ubuntu2.1 | 
| mantic | released  | 2.38-1ubuntu5 | 
| noble | released  | 2.38-1ubuntu5 | 
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
A flaw was found in glibc. When the getaddrinfo function is called wit ...
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
EPSS
6.5 Medium
CVSS3