// For flags

CVE-2023-4806

Glibc: potential use-after-free in getaddrinfo()

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.

Se encontró una falla en glibc. En una situación extremadamente rara, la función getaddrinfo puede acceder a la memoria que se ha liberado, lo que provoca un bloqueo de la aplicación. Este problema solo se puede explotar cuando un módulo NSS implementa solo los hooks _nss_*_gethostbyname2_r y _nss_*_getcanonname_r sin implementar el hook _nss_*_gethostbyname3_r. El nombre resuelto debe devolver una gran cantidad de direcciones IPv6 e IPv4, y la llamada a la función getaddrinfo debe tener la familia de direcciones AF_INET6 con AI_CANONNAME, AI_ALL y AI_V4MAPPED como indicadores.

*Credits: This issue was discovered by Siddhesh Poyarekar (Red Hat).
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-09-06 CVE Reserved
  • 2023-09-18 CVE Published
  • 2024-10-20 EPSS Updated
  • 2024-11-15 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-416: Use After Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gnu
Search vendor "Gnu"
Glibc
Search vendor "Gnu" for product "Glibc"
2.33
Search vendor "Gnu" for product "Glibc" and version "2.33"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder Eus
Search vendor "Redhat" for product "Codeready Linux Builder Eus"
9.2
Search vendor "Redhat" for product "Codeready Linux Builder Eus" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder Eus For Power Little Endian
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian"
9.0_ppc64le
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian" and version "9.0_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder Eus For Power Little Endian Eus
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian Eus"
9.2_ppc64le
Search vendor "Redhat" for product "Codeready Linux Builder Eus For Power Little Endian Eus" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Arm64
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64"
9.0_aarch64
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64" and version "9.0_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Arm64 Eus
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64 Eus"
9.2_aarch64
Search vendor "Redhat" for product "Codeready Linux Builder For Arm64 Eus" and version "9.2_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Ibm Z Systems
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems"
9.0_s390x
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems" and version "9.0_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Codeready Linux Builder For Ibm Z Systems Eus
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems Eus"
9.2_s390x
Search vendor "Redhat" for product "Codeready Linux Builder For Ibm Z Systems Eus" and version "9.2_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
7.0
Search vendor "Redhat" for product "Enterprise Linux" and version "7.0"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
8.0
Search vendor "Redhat" for product "Enterprise Linux" and version "8.0"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
9.0
Search vendor "Redhat" for product "Enterprise Linux" and version "9.0"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Eus
Search vendor "Redhat" for product "Enterprise Linux Eus"
8.8
Search vendor "Redhat" for product "Enterprise Linux Eus" and version "8.8"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Eus
Search vendor "Redhat" for product "Enterprise Linux Eus"
9.2
Search vendor "Redhat" for product "Enterprise Linux Eus" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Arm 64
Search vendor "Redhat" for product "Enterprise Linux For Arm 64"
9.0_aarch64
Search vendor "Redhat" for product "Enterprise Linux For Arm 64" and version "9.0_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Arm 64 Eus
Search vendor "Redhat" for product "Enterprise Linux For Arm 64 Eus"
9.2_aarch64
Search vendor "Redhat" for product "Enterprise Linux For Arm 64 Eus" and version "9.2_aarch64"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems"
8.0_s390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems" and version "8.0_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems Eus
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus"
8.8_s390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus" and version "8.8_s390x"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems Eus S390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus S390x"
9.2
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems Eus S390x" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Ibm Z Systems S390x
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems S390x"
9.2
Search vendor "Redhat" for product "Enterprise Linux For Ibm Z Systems S390x" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian"
8.0_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian" and version "8.0_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian"
9.2_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian Eus
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus"
8.8_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus" and version "8.8_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux For Power Little Endian Eus
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus"
9.2_ppc64le
Search vendor "Redhat" for product "Enterprise Linux For Power Little Endian Eus" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Server Aus
Search vendor "Redhat" for product "Enterprise Linux Server Aus"
9.2
Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "9.2"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Search vendor "Redhat" for product "Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions"
9.2_ppc64le
Search vendor "Redhat" for product "Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions" and version "9.2_ppc64le"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Linux Tus
Search vendor "Redhat" for product "Enterprise Linux Tus"
8.8
Search vendor "Redhat" for product "Enterprise Linux Tus" and version "8.8"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
37
Search vendor "Fedoraproject" for product "Fedora" and version "37"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
38
Search vendor "Fedoraproject" for product "Fedora" and version "38"
-
Affected
Fedoraproject
Search vendor "Fedoraproject"
Fedora
Search vendor "Fedoraproject" for product "Fedora"
39
Search vendor "Fedoraproject" for product "Fedora" and version "39"
-
Affected