CVE-2023-4806

medium
Published 2024-04-30 Β· Modified 2023-10-05
CVSS v3
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.9

Description

RHSA-2023:5455: glibc security update (Important)

Predictions

Exploit likelihood
69%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description glibc: potential use-after-free in getaddrinfo() Red Hat statement This issue is only exploitable with very specific conditions, as detailed in the description. However, all glibc versions shipped in Red Hat Enterprise Linux are vulnerable to this issue. CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat…

Description

glibc: potential use-after-free in getaddrinfo()

Red Hat statement

This issue is only exploitable with very specific conditions, as detailed in the description. However, all glibc versions shipped in Red Hat Enterprise Linux are vulnerable to this issue.

CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8glibc-0:2.28-225.el8_8.6RHSA-2023:54552023-10-05T00:00:00Z
Red Hat Enterprise Linux 8glibc-0:2.28-225.el8_8.6RHSA-2023:54552023-10-05T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportglibc-0:2.28-189.8.el8_6RHSA-2023:74092023-11-21T00:00:00Z
Red Hat Enterprise Linux 9glibc-0:2.34-100.el9RHBA-2024:24132024-04-30T00:00:00Z
Red Hat Enterprise Linux 9glibc-0:2.34-60.el9_2.7RHSA-2023:54532023-10-05T00:00:00Z
Red Hat Enterprise Linux 9glibc-0:2.34-100.el9RHBA-2024:24132024-04-30T00:00:00Z
Red Hat Enterprise Linux 9glibc-0:2.34-60.el9_2.7RHSA-2023:54532023-10-05T00:00:00Z
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8glibc-0:2.28-189.8.el8_6RHSA-2023:74092023-11-21T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6compat-glibcOut of support scope
Red Hat Enterprise Linux 6glibcOut of support scope
Red Hat Enterprise Linux 7compat-glibcWill not fix
Red Hat Enterprise Linux 7glibcWill not fix

Apply commands

bash fix
Apply RHSA-2023:5455 for Red Hat Enterprise Linux 8
yum update -y glibc
# or:
dnf upgrade -y glibc

OS impact

fedora Fedora Affected 3 releases
VersionStatusFixed in
39 Affected β€”
38 Affected β€”
37 Affected β€”
suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Fixed 2.37-10
sid Fixed 2.37-10
forky Fixed 2.37-10
bullseye Affected β€”
bookworm Fixed 2.36-9+deb12u3
redhat Red Hat Mixed 8 releases
VersionStatusFixed in
9.2 Affected β€”
9.0_aarch64 Affected β€”
9.0 Affected β€”
9 Fixed β€”
8.8 Affected β€”
8.0 Affected β€”
8 Fixed β€”
7.0 Affected β€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed glibc-locale-source-2.34-60.el9_2.7.aarch64.rpm
8 Fixed glibc-doc-2.28-225.el8_8.6.noarch.rpm
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

Application impact

References

CWEs

CWE-416

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.