Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade glibc-headersUpgrade nscdUpgrade glibc-staticUpgrade glibc-develUpgrade glibc-commonUpgrade glibc-utilsUpgrade glibc | Jul 6, 2016 | Feb 17, 2016 |
| Cisco Ise | — | — | Oct 21, 2025 | Feb 18, 2016 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Feb 18, 2016 |
| Debian | — | Upgrade eglibcUpgrade glibc | Feb 18, 2016 | Feb 16, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Feb 17, 2016 |
| Freebsd | — | Upgrade linux_base-c6_64Upgrade linux_base-f10Upgrade linux_base-c6 | Dec 10, 2025 | Feb 18, 2016 |
| Gentoo Linux | — | Upgrade sys-libs/glibc. | Oct 30, 2017 | Feb 18, 2016 |
| Oracle_linux | — | Upgrade glibc-develUpgrade glibc-headersUpgrade glibc-commonUpgrade nscdUpgrade glibc-staticUpgrade glibcUpgrade glibc-utils | Jul 1, 2017 | Feb 18, 2016 |
| Panos | — | Update PAN-OS 6.0 to the latest workaround for your deviceUpgrade PAN-OS 7.0 to the latest versionUpdate PAN-OS 5.1 to the latest workaround for your deviceUpdate PAN-OS 7.1 to the latest workaround for your deviceUpdate PAN-OS 6.1 to the latest workaround for your deviceUpdate PAN-OS 5.0 to the latest workaround for your device | Oct 12, 2016 | Feb 18, 2016 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.2R2Update Pulse Connect Secure to version 8.1R8 | Oct 28, 2020 | Feb 18, 2016 |
| Redhat_linux | — | No solution exists | Jul 16, 2026 | Feb 16, 2016 |
| Suse | — | Upgrade glibc-infoUpgrade glibc-32bitUpgrade glibc-develUpgrade certification-sles-eal4Upgrade glibc-locale-x86Upgrade glibc-i18ndataUpgrade glibc-profileUpgrade glibc-extraUpgrade glibc-devel-staticUpgrade glibc-locale-baseUpgrade glibc-profile-32bitUpgrade sles11sp4-docker-imageUpgrade glibc-locale-base-32bitUpgrade glibc-localeUpgrade glibc-utilsUpgrade sles12sp1-docker-imageUpgrade glibc-x86Upgrade sles12-docker-imageUpgrade glibcUpgrade glibc-devel-32bitUpgrade glibc-locale-32bitUpgrade glibc-profile-x86Upgrade nscdUpgrade glibc-htmlUpgrade glibc-lang | Feb 18, 2016 | Feb 16, 2016 |
| Ubuntu | — | Upgrade libc6 | Feb 18, 2016 | Feb 16, 2016 |
| Vmsa 2016 0002 | — | Upgrade VMware ESXi 5.5 to build number 3568722Upgrade VMware ESXi 6.0 to build number 3568940 | Oct 20, 2016 | Feb 18, 2016 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub