CVE-2026-0915
published 2026-01-15CVE-2026-0915: Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.56%
43.2th percentile
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.42-8 (forky) | glibc 2.42-8 (forky) |
| gnu | glibc | >= 0 < 2.41-12+deb13u2 | 2.41-12+deb13u2 |
| gnu | glibc | >= 0 < 2.42-8 | 2.42-8 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.13 | 2.35-0ubuntu3.13 |
| gnu | glibc | >= 0 < 2.39-0ubuntu8.7 | 2.39-0ubuntu8.7 |
| gnu | glibc | >= 0 < 2.42-0ubuntu3.1 | 2.42-0ubuntu3.1 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm9 | 2.23-0ubuntu11.3+esm9 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.6+esm6 | 2.27-3ubuntu1.6+esm6 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.18+esm1 | 2.31-0ubuntu9.18+esm1 |
| gnu | glibc | 2.0 – 2.42 | — |
| the_gnu_c_library | glibc | 2.0 – 2.42 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2026-02-03·CVSS 7.5
CVE-2026-0861 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
Vitaly Simonovich discovered that the GNU C Library did not properly
initialize the input when WRDE_REUSE is used. An attacker could possibly
use this issue to cause applications to crash, leading to a denial of
service. (CVE-2025-15281)
Anastasia Belova discovered that the GNU C Library incorrectly handled
the regcomp function when memory allocation failures occured. An attacker
could possibly use this issue to cause applications to crash, leading to
a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2025-8058)
Igor Morgenstern discovered that the GNU C Library incorrectly handled
the memalign fu
Red Hat
glibc: glibc: Information disclosure via zero-valued network query
vendor_redhat·2026-01-15·CVSS 7.5
CVE-2026-0915 [HIGH] CWE-908 glibc: glibc: Information disclosure via zero-valued network query
glibc: glibc: Information disclosure via zero-valued network query
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
A flaw was found in glibc, the GNU C Library. When an application calls the `getnetbyaddr` or `getnetbyaddr_r` functions to resolve a network address, and the system's `nsswitch.conf` file is configured to use a DNS (Domain Name System) backend for network lookups, a query for a zero-valued network can lead to the disclosure of stack memory contents. This information is leaked to the configured DNS resolver, potentially allowing an attacker who controls the r
Debian
CVE-2026-0915: glibc - Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec...
vendor_debian·2026·CVSS 7.5
CVE-2026-0915 [HIGH] CVE-2026-0915: glibc - Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that spec...
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.42-8)
sid: resolved (fixed in 2.42-8)
trixie: resolved (fixed in 2.41-12+deb13u2)
OSV
glibc vulnerabilities
osv·2026-02-03·CVSS 7.5
CVE-2025-15281 [HIGH] glibc vulnerabilities
glibc vulnerabilities
Vitaly Simonovich discovered that the GNU C Library did not properly
initialize the input when WRDE_REUSE is used. An attacker could possibly
use this issue to cause applications to crash, leading to a denial of
service. (CVE-2025-15281)
Anastasia Belova discovered that the GNU C Library incorrectly handled
the regcomp function when memory allocation failures occured. An attacker
could possibly use this issue to cause applications to crash, leading to
a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2025-8058)
Igor Morgenstern discovered that the GNU C Library incorrectly handled
the memalign function when doing memory allocation. An attacker could
possibly use this issue
GHSA
GHSA-xp56-6525-9chf: Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch
ghsa_unreviewed·2026-01-16
CVE-2026-0915 [HIGH] CWE-908 GHSA-xp56-6525-9chf: Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
OSV
CVE-2026-0915: Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch
osv·2026-01-15·CVSS 7.5
CVE-2026-0915 [HIGH] CVE-2026-0915: Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0915 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-0915 [HIGH] CVE-2026-0915 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0915 :
NixOS vulnerability analysis and mitigation
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
Source : NVD
## 7.5
Score
Published January 15, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
glibc-langpack-cs
glibc-langpack-raj
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 20, 2026
AlmaL
Bugzilla
CVE-2026-0915 glibc: glibc: Information disclosure via zero-valued network query
bugzilla·2026-01-15·CVSS 7.5
CVE-2026-0915 [HIGH] CVE-2026-0915 glibc: glibc: Information disclosure via zero-valued network query
CVE-2026-0915 glibc: glibc: Information disclosure via zero-valued network query
Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:1334 https://access.redhat.com/errata/RHSA-2026:1334
---
This comment was flagged as spam, view the edit history to see the original text if required.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:2786 https://access.redhat.com/errata/RHSA-2026:2786
---
This issue has be
2026-01-15
Published