Back

MEDIUM

Glibc: stack read overflow in getaddrinfo in no-aaaa mode

Published Sep 18, 2023

Description

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

Affected products

Remediation

Vendor solution

Removing the no-aaaa diagnostic option from /etc/resolv.conf will mitigate this flaw.

Red Hat statement

This issue only affects systems configured with no-aaaa mode via /etc/resolv.conf. The no-aaaa stub resolver option was backported only to Red Hat Enterprise Linux versions 8.7 and 9.1. Therefore, previous versions are not affected.

Red Hat mitigation

Removing the no-aaaa diagnostic option from /etc/resolv.conf will mitigate this flaw.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 18, 2023
Updated Jul 14, 2026
Reserved Aug 24, 2023
CISA Vulnrichment
Updated Dec 3, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 12, 2023