Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the librarys DNS backend in the GNU C Library version 2.34 to version 2.43 could, with a crafted response from the configured DNS server, result in a violation of the DNS specification that causes the application to treat a non-answer section of the DNS response as a valid answer.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Glibc | Gnu | 2.34 (including) | 2.43 (including) |
| Red Hat Enterprise Linux 10 | RedHat | glibc-0:2.39-121.el10_2 | * |
| Red Hat Enterprise Linux 9 | RedHat | glibc-0:2.34-270.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | glibc-0:2.34-270.el9_8 | * |
| Cert Manager support for Red Hat OpenShift release 1.20 | RedHat | cert-manager/cert-manager-trust-manager-rhel9:1790598593 | * |
| Cost Management 4 | RedHat | costmanagement/costmanagement-metrics-rhel9-operator:1780946239 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-server-rhel9:1782159791 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-ui-rhel9:1782166952 | * |
| Red Hat Hardened Images | RedHat | glibc-main-2.42-11.1.hum1 | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:1780420428 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1781525684 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1781525671 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1781525693 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1781525739 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-kubernetes-tp-rhel9:1787241211 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-tp-rhel9:1787135742 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-tp-rhel9:1787241260 | * |
| Glibc | Ubuntu | noble | * |
| Glibc | Ubuntu | questing | * |