Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-commonUpgrade glibc-utilsUpgrade glibc-develUpgrade glibcUpgrade glibc-staticUpgrade nscdUpgrade glibc-headers | Jul 6, 2016 | Feb 17, 2016 |
| Cisco Ise | — | — | Oct 21, 2025 | Feb 18, 2016 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Feb 18, 2016 |
| Debian | — | Upgrade glibcUpgrade eglibc | Feb 18, 2016 | Feb 16, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 17, 2016 |
| Freebsd | — | Upgrade linux_base-c6_64Upgrade linux_base-f10Upgrade linux_base-c6 | Dec 10, 2025 | Feb 18, 2016 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Feb 18, 2016 |
| Oracle_linux | — | Upgrade glibc-staticUpgrade glibcUpgrade glibc-utilsUpgrade glibc-commonUpgrade glibc-headersUpgrade glibc-develUpgrade nscd | Jul 1, 2017 | Feb 18, 2016 |
| Panos | — | Update PAN-OS 7.1 to the latest workaround for your deviceUpdate PAN-OS 5.1 to the latest workaround for your deviceUpdate PAN-OS 6.0 to the latest workaround for your deviceUpgrade PAN-OS 7.0 to the latest versionUpdate PAN-OS 5.0 to the latest workaround for your deviceUpdate PAN-OS 6.1 to the latest workaround for your device | Oct 12, 2016 | Feb 18, 2016 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.2R2Update Pulse Connect Secure to version 8.1R8 | Oct 28, 2020 | Feb 18, 2016 |
| Redhat_linux | — | No solution exists | Jul 16, 2026 | Feb 16, 2016 |
| Suse | — | Upgrade glibc-profile-x86Upgrade glibc-devel-32bitUpgrade glibcUpgrade glibc-locale-32bitUpgrade sles12-docker-imageUpgrade glibc-htmlUpgrade nscdUpgrade glibc-langUpgrade glibc-profileUpgrade certification-sles-eal4Upgrade glibc-infoUpgrade glibc-locale-x86Upgrade glibc-32bitUpgrade glibc-utilsUpgrade glibc-locale-baseUpgrade glibc-locale-base-32bitUpgrade glibc-profile-32bitUpgrade glibc-devel-staticUpgrade sles11sp4-docker-imageUpgrade sles12sp1-docker-imageUpgrade glibc-develUpgrade glibc-x86Upgrade glibc-localeUpgrade glibc-extraUpgrade glibc-i18ndata | Feb 18, 2016 | Feb 16, 2016 |
| Ubuntu | — | Upgrade libc6 | Feb 18, 2016 | Feb 16, 2016 |
| Vmsa 2016 0002 | — | Upgrade VMware ESXi 5.5 to build number 3568722Upgrade VMware ESXi 6.0 to build number 3568940 | Oct 20, 2016 | Feb 18, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub