CVE-2023-5156
published 2023-09-25CVE-2023-5156: A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.34%
68.1th percentile
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.37-11 (forky) | glibc 2.37-11 (forky) |
| gnu | glibc | >= 0 < 2.37-11 | 2.37-11 |
| gnu | glibc | >= 0 < 2.37-11 | 2.37-11 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.14 | 2.31-0ubuntu9.14 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.6 | 2.35-0ubuntu3.6 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.5 | 2.35-0ubuntu3.5 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm5 | 2.23-0ubuntu11.3+esm5 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.6+esm1 | 2.27-3ubuntu1.6+esm1 |
| gnu | glibc | >= 2.34 < 2.39 | 2.39 |
| msrc | azl3_glibc_2.38-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_glibc_2.38-6_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_glibc_2.35-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_msrc7.5HIGH
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library regression
vendor_ubuntu·2024-01-10·CVSS 5.9
CVE-2023-4806 [MEDIUM] GNU C Library regression
Title: GNU C Library regression
Summary: USN-6541-1 introduced a regression in the GNU C Library.
USN-6541-1 fixed vulnerabilities in the GNU C Library. Unfortunately,
changes made to allow proper application of the fix for CVE-2023-4806 in
Ubuntu 22.04 LTS introduced an issue in the NSCD service IPv6 processing
functionalities. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the GNU C Library was not properly handling certain
memory operations. An attacker could possibly use this issue to cause a
denial of service (application crash). (CVE-2023-4806, CVE-2023-4813)
It was discovered that the GNU C library was not properly implementing a
fix for CVE-2023-4806 in certain cases, which could lead to a memory leak.
An a
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2023-12-07·CVSS 5.9
CVE-2023-4806 [MEDIUM] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
It was discovered that the GNU C Library was not properly handling certain
memory operations. An attacker could possibly use this issue to cause a
denial of service (application crash). (CVE-2023-4806, CVE-2023-4813)
It was discovered that the GNU C library was not properly implementing a
fix for CVE-2023-4806 in certain cases, which could lead to a memory leak.
An attacker could possibly use this issue to cause a denial of service
(application crash). This issue only affected Ubuntu 22.04 LTS and Ubuntu
23.04. (CVE-2023-5156)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
glibc: DoS due to memory leak in getaddrinfo.c
vendor_redhat·2023-09-25·CVSS 5.9
CVE-2023-5156 [MEDIUM] CWE-401 glibc: DoS due to memory leak in getaddrinfo.c
glibc: DoS due to memory leak in getaddrinfo.c
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
Package: compat-glibc (Red Hat Enterprise Linux 6) - Out of support scope
Package: glibc (Red Hat Enterprise Linux 6) - Out of support scope
Package: compat-glibc (Red Hat Enterprise Linux 7) - Out of support scope
Package: glibc (Red Hat Enterprise Linux 7) - Out of support scope
Package: glibc (Red Hat Enterprise Linux 8) - Not affected
Package: glibc (Red Hat Enterprise Linux 9) - Not affected
Microsoft
Glibc: dos due to memory leak in getaddrinfo.c
vendor_msrc·2023-09-12·CVSS 7.5
CVE-2023-5156 [HIGH] CWE-401 Glibc: dos due to memory leak in getaddrinfo.c
Glibc: dos due to memory leak in getaddrinfo.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micros
Debian
CVE-2023-5156: glibc - A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced...
vendor_debian·2023·CVSS 5.9
CVE-2023-5156 [MEDIUM] CVE-2023-5156: glibc - A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced...
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2.37-11)
sid: resolved (fixed in 2.37-11)
trixie: resolved (fixed in 2.37-11)
OSV
glibc regression
osv·2024-01-10·CVSS 5.9
CVE-2023-4806 [MEDIUM] glibc regression
glibc regression
USN-6541-1 fixed vulnerabilities in the GNU C Library. Unfortunately,
changes made to allow proper application of the fix for CVE-2023-4806 in
Ubuntu 22.04 LTS introduced an issue in the NSCD service IPv6 processing
functionalities. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the GNU C Library was not properly handling certain
memory operations. An attacker could possibly use this issue to cause a
denial of service (application crash). (CVE-2023-4806, CVE-2023-4813)
It was discovered that the GNU C library was not properly implementing a
fix for CVE-2023-4806 in certain cases, which could lead to a memory leak.
An attacker could possibly use this issue to cause a denial of service
(application cr
OSV
glibc vulnerabilities
osv·2023-12-07·CVSS 5.9
CVE-2023-4806 [MEDIUM] glibc vulnerabilities
glibc vulnerabilities
It was discovered that the GNU C Library was not properly handling certain
memory operations. An attacker could possibly use this issue to cause a
denial of service (application crash). (CVE-2023-4806, CVE-2023-4813)
It was discovered that the GNU C library was not properly implementing a
fix for CVE-2023-4806 in certain cases, which could lead to a memory leak.
An attacker could possibly use this issue to cause a denial of service
(application crash). This issue only affected Ubuntu 22.04 LTS and Ubuntu
23.04. (CVE-2023-5156)
GHSA
GHSA-m7p3-g2hx-xfc3: A flaw was found in the GNU C Library
ghsa_unreviewed·2023-09-25·CVSS 5.9
CVE-2023-5156 [MEDIUM] CWE-401 GHSA-m7p3-g2hx-xfc3: A flaw was found in the GNU C Library
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
OSV
CVE-2023-5156: A flaw was found in the GNU C Library
osv·2023-09-25·CVSS 5.9
CVE-2023-5156 [MEDIUM] CVE-2023-5156: A flaw was found in the GNU C Library
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/CVE-2023-5156https://bugzilla.redhat.com/show_bug.cgi?id=2240541https://sourceware.org/bugzilla/show_bug.cgi?id=30884https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=ec6b95c3303c700eb89eebeda2d7264cc184a796http://www.openwall.com/lists/oss-security/2023/10/03/4http://www.openwall.com/lists/oss-security/2023/10/03/5http://www.openwall.com/lists/oss-security/2023/10/03/6http://www.openwall.com/lists/oss-security/2023/10/03/8https://access.redhat.com/security/cve/CVE-2023-5156https://bugzilla.redhat.com/show_bug.cgi?id=2240541https://security.gentoo.org/glsa/202402-01https://sourceware.org/bugzilla/show_bug.cgi?id=30884https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=ec6b95c3303c700eb89eebeda2d7264cc184a796
2023-09-25
Published