Loading HuntDB...

GHSA-hmf7-f8gf-8f4p

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

Related CVEs

Key Information

GHSA ID
GHSA-hmf7-f8gf-8f4p
Published
September 18, 2023 6:30 PM
Last Modified
September 16, 2024 2:37 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.