Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the librarys DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
The product uses or accesses a resource that has not been initialized.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Glibc | Gnu | 2.0 (including) | 2.42 (including) |
| Red Hat Enterprise Linux 10 | RedHat | glibc-0:2.39-58.el10_1.7 | * |
| Eglibc | Ubuntu | esm-infra-legacy/trusty | * |
| Glibc | Ubuntu | devel | * |
| Glibc | Ubuntu | esm-infra/bionic | * |
| Glibc | Ubuntu | esm-infra/focal | * |
| Glibc | Ubuntu | esm-infra/xenial | * |
| Glibc | Ubuntu | jammy | * |
| Glibc | Ubuntu | noble | * |
| Glibc | Ubuntu | questing | * |
| Glibc | Ubuntu | upstream | * |