glibc: Fragmentation attacks possible when EDNS0 is enabled
Published Aug 1, 2017
5.9
MEDIUMCVSS 3.0
EPSS 1.96%
Description
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
Affected products
No data.
No data.
Red Hat Enterprise Linux 7
glibc-0:2.17-222.el7
Fixed · RHSA-2018:0805
Red Hat Enterprise Linux 5
compat-glibc
Will not fix
Red Hat Enterprise Linux 5
glibc
Will not fix
Red Hat Enterprise Linux 6
compat-glibc
Will not fix
Red Hat Enterprise Linux 6
glibc
Will not fix
Red Hat Enterprise Linux 7
compat-glibc
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | glibc-0:2.17-222.el7 | Fixed | RHSA-2018:0805 |
| Red Hat Enterprise Linux 5 | compat-glibc | Will not fix | n/a |
| Red Hat Enterprise Linux 5 | glibc | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | compat-glibc | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | glibc | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | compat-glibc | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue only affects systems which use a remote recursive resolver and enable EDNS0, either with the “edns0” option in /etc/resolv.conf, or using the RES_USE_EDNS0 or RES_USE_DNSSEC resolver flags. The underlying issue affects recursive resolvers such as BIND and Unbound as well, and has to be fixed separately there.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.96% (0.01958) | 79.60th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.96% (0.01958) | 79.41th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.19% (0.00186) | 56.35th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.19% (0.00186) | 55.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.32% (0.00320) | 65.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (8)
- http://www.securityfocus.com/bid/100598 vdb-entryx_refsource_BID
- https://access.redhat.com/errata/RHSA-2018:0805 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-12132 Vendor Advisory
- https://arxiv.org/pdf/1205.4011.pdf x_refsource_MISCTechnical DescriptionThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1477529 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-12132
- https://sourceware.org/bugzilla/show_bug.cgi?id=21361 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-12132
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/100598 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/errata/RHSA-2018:0805 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2017-12132 | Vendor Advisory | |
| https://arxiv.org/pdf/1205.4011.pdf | x_refsource_MISCTechnical DescriptionThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1477529 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-12132 | ||
| https://sourceware.org/bugzilla/show_bug.cgi?id=21361 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-12132 |
Change history (0)
No recorded changes yet.