Severity
7.5HIGHNVD
EPSS
1.8%
top 17.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 4
Latest updateMay 13

Description

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debiangnu/glibc< 2.28-1+3
NVDgnu/glibc2.28

Also affects: Fedora 28, 29

🔴Vulnerability Details

3
GHSA
GHSA-x2fw-rj3g-6m95: In the GNU C Library (aka glibc or libc6) through 22022-05-13
OSV
CVE-2018-19591: In the GNU C Library (aka glibc or libc6) through 22018-12-04
CVEList
CVE-2018-19591: In the GNU C Library (aka glibc or libc6) through 22018-12-04

📋Vendor Advisories

4
Ubuntu
GNU C Library vulnerabilities2020-07-06
Microsoft
In the GNU C Library (aka glibc or libc6) through 2.28 attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to 2018-12-11
Red Hat
glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c2018-11-27
Debian
CVE-2018-19591: glibc - In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a ...2018

💬Community

2
Bugzilla
CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c [fedora-all]2018-11-27
Bugzilla
CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c2018-11-27
CVE-2018-19591 — Improper Input Validation in GNU Glibc | cvebase