cbcvebase.
CVE-2023-4813
published 2023-09-12

CVE-2023-4813: A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash…

medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

Affected

23 ranges
VendorProductVersion rangeFixed in
debianglibc< glibc 2.36-3 (bookworm)glibc 2.36-3 (bookworm)
fedoraprojectfedora
gnuglibc< 2.362.36
gnuglibc>= 0 < 2.36-32.36-3
gnuglibc>= 0 < 2.36-32.36-3
gnuglibc>= 0 < 2.36-32.36-3
gnuglibc>= 0 < 2.31-0ubuntu9.142.31-0ubuntu9.14
gnuglibc>= 0 < 2.35-0ubuntu3.62.35-0ubuntu3.6
gnuglibc>= 0 < 2.35-0ubuntu3.52.35-0ubuntu3.5
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm52.23-0ubuntu11.3+esm5
gnuglibc>= 0 < 2.27-3ubuntu1.6+esm12.27-3ubuntu1.6+esm1
msrccbl2_glibc_2.35-7_on_cbl_mariner_2.0
paloaltopan-os
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_for_ibm_z_systems_eus_s390x
redhatenterprise_linux_for_ibm_z_systems_s390x
redhatenterprise_linux_for_power_little_endian
redhatenterprise_linux_for_power_little_endian_eus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM