Glibc: stack read overflow in getaddrinfo in no-aaaa mode
Published Sep 18, 2023
6.5
MEDIUMCVSS 3.1
EPSS 1.67%
Description
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
Affected products
No data.
Configuration 1
Configuration 2
- 9.2
- 9.0_ppc64le
- 9.2_ppc64le
- 9.0_aarch64
- 9.2_aarch64
- 9.0_s390x
- 9.2_s390x
- 8.0
- 9.0
- 8.8
- 9.2
- 9.0_aarch64
- 9.2_aarch64
- 8.0_s390x
- 8.8_s390x
- 9.2
- 9.2
- 8.0_ppc64le
- 9.2_ppc64le
- 8.8_ppc64le
- 9.2_ppc64le
- 9.2
- 9.2_ppc64le
- 8.8
Configuration 3
- 37
- 38
- 39
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
No data.
Red Hat Enterprise Linux 8
glibc-0:2.28-225.el8_8.6
Fixed · RHSA-2023:5455
Red Hat Enterprise Linux 8
glibc-0:2.28-225.el8_8.6
Fixed · RHSA-2023:5455
Red Hat Enterprise Linux 9
glibc-0:2.34-60.el9_2.7
Fixed · RHSA-2023:5453
Red Hat Enterprise Linux 9
glibc-0:2.34-60.el9_2.7
Fixed · RHSA-2023:5453
Red Hat Enterprise Linux 6
compat-glibc
Not affected
Red Hat Enterprise Linux 6
glibc
Not affected
Red Hat Enterprise Linux 7
compat-glibc
Not affected
Red Hat Enterprise Linux 7
glibc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | glibc-0:2.28-225.el8_8.6 | Fixed | RHSA-2023:5455 |
| Red Hat Enterprise Linux 8 | glibc-0:2.28-225.el8_8.6 | Fixed | RHSA-2023:5455 |
| Red Hat Enterprise Linux 9 | glibc-0:2.34-60.el9_2.7 | Fixed | RHSA-2023:5453 |
| Red Hat Enterprise Linux 9 | glibc-0:2.34-60.el9_2.7 | Fixed | RHSA-2023:5453 |
| Red Hat Enterprise Linux 6 | compat-glibc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | glibc | Not affected | n/a |
| Red Hat Enterprise Linux 7 | compat-glibc | Not affected | n/a |
| Red Hat Enterprise Linux 7 | glibc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Removing the no-aaaa diagnostic option from /etc/resolv.conf will mitigate this flaw.
Red Hat statement
This issue only affects systems configured with no-aaaa mode via /etc/resolv.conf. The no-aaaa stub resolver option was backported only to Red Hat Enterprise Linux versions 8.7 and 9.1. Therefore, previous versions are not affected.
Red Hat mitigation
Removing the no-aaaa diagnostic option from /etc/resolv.conf will mitigate this flaw.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 3, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.67% (0.01669) | 75.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.51% (0.01508) | 71.00th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.11% (0.00108) | 29.74th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.83% (0.01834) | 81.44th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.10% (0.00105) | 29.80th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.47% (0.01473) | 79.16th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.45% (0.03451) | 78.98th | v4 (v2025.03.14) |
| Mar 28, 2025 | 1.47% (0.01473) | 79.17th | v4 (v2025.03.14) |
| Mar 27, 2025 | 3.45% (0.03451) | 85.97th | v4 (v2025.03.14) |
| Mar 25, 2025 | 1.47% (0.01473) | 79.07th | v4 (v2025.03.14) |
| Mar 24, 2025 | 3.45% (0.03451) | 86.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.47% (0.01473) | 79.62th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.14% (0.00142) | 51.43th | v3 (v2023.03.01) |
| Dec 29, 2023 | 0.09% (0.00091) | 38.16th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.06% (0.00063) | 25.31th | v3 (v2023.03.01) |
| Oct 27, 2023 | 0.07% (0.00066) | 27.53th | v3 (v2023.03.01) |
| Oct 6, 2023 | 0.08% (0.00077) | 31.88th | v3 (v2023.03.01) |
| Oct 5, 2023 | 0.07% (0.00068) | 28.06th | v3 (v2023.03.01) |
| Sep 26, 2023 | 0.05% (0.00049) | 16.31th | v3 (v2023.03.01) |
| Sep 22, 2023 | 0.05% (0.00046) | 14.21th | v3 (v2023.03.01) |
| Sep 19, 2023 | 0.04% (0.00043) | 7.20th | v3 (v2023.03.01) |
References (14)
- http://www.openwall.com/lists/oss-security/2023/09/25/1 Mailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5453 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:5455 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-4527 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2234712 issue-trackingx_refsource_REDHATExploitIssue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://cert-portal.siemens.com/productcert/html/ssa-831302.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4527
- https://security.gentoo.org/glsa/202310-03 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20231116-0012/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-4527
Change history (0)
No recorded changes yet.