Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the librarys DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
The product uses or accesses a resource that has not been initialized.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Glibc | Gnu | 2.0 (including) | 2.42 (including) |
| Red Hat Enterprise Linux 10 | RedHat | glibc-0:2.39-58.el10_1.7 | * |
| Red Hat Enterprise Linux 9 | RedHat | glibc-0:2.34-231.el9_7.10 | * |
| Red Hat Enterprise Linux 9 | RedHat | glibc-0:2.34-231.el9_7.10 | * |
| Cost Management 4 | RedHat | costmanagement/costmanagement-metrics-rhel9-operator:sha256:7424ae28625701b1441987b0457100505e273b2cbcb087bf0c046d7b2cc596c7 | * |
| Eglibc | Ubuntu | esm-infra-legacy/trusty | * |
| Glibc | Ubuntu | devel | * |
| Glibc | Ubuntu | esm-infra/bionic | * |
| Glibc | Ubuntu | esm-infra/focal | * |
| Glibc | Ubuntu | esm-infra/xenial | * |
| Glibc | Ubuntu | jammy | * |
| Glibc | Ubuntu | noble | * |
| Glibc | Ubuntu | questing | * |
| Glibc | Ubuntu | upstream | * |