Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade glibcUpgrade eglibc | Jul 30, 2024 | Dec 12, 2013 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Dec 12, 2013 |
| Oracle_linux | — | Upgrade glibc-commonUpgrade glibc-develUpgrade glibcUpgrade glibc-utilsUpgrade nscdUpgrade glibc-headersUpgrade glibc-static | Oct 16, 2024 | Dec 12, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 22, 2013 |
| Suse | — | Upgrade glibc-profile-32bitUpgrade glibc-32bitUpgrade glibc-i18ndataUpgrade glibc-infoUpgrade glibc-locale-x86Upgrade glibc-develUpgrade glibc-devel-32bitUpgrade glibc-htmlUpgrade glibc-profileUpgrade glibc-localeUpgrade glibc-x86Upgrade glibc-locale-32bitUpgrade glibc-profile-x86Upgrade sle-sdk-releaseUpgrade glibcUpgrade nscd | Jun 17, 2014 | Dec 12, 2013 |
| Ubuntu | — | Upgrade libc6 | Nov 8, 2024 | Dec 12, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub