CVE-2023-4527: Glibc: stack read overflow in getaddrinfo in no-aaaa mode

Published Aug 25, 2023
·
Updated

A flaw was found in glibc. When the getaddrinfo function is called with the AFUNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

Other sources

glibc is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the getaddrinfo function. By sending a DNS response over TCP larger than 2048 bytes, a remote attacker could overflow a buffer, allowing an attacker to obtain sensitive information or cause a denial of service.

IBM

Glibc: stack read overflow in getaddrinfo in no-aaaa mode

Microsoft

If the system is configured in no-aaaa mode via /etc/resolv.conf, getaddrinfo is called for the AFUNSPEC address family, and a DNS response is received over TCP that is larger than 2048 bytes, getaddrinfo may potentially disclose stack contents via the returned address data, or crash. While name lookup normally just fails incorrectly, crashes are not difficult to trigger, with valid DNS responses that are propagated by DNS resolvers.

Reference: https://sourceware.org/bugzilla/showbug.cgi?id=30842

Red Hat

Affected Software

47 affected componentsFixes available
debian/glibc<=2.36-9+deb12u2
2.28-10+deb10u12.28-10+deb10u22.31-13+deb11u62.31-13+deb11u72.36-9+deb12u32.37-12
ubuntu/glibc<2.37-0ubuntu2.1
2.37-0ubuntu2.1
ubuntu/glibc<2.38-1ubuntu5
2.38-1ubuntu5
GNU glibc<2.39
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Codeready Linux Builder Eus=9.2
redhat Codeready Linux Builder Eus For Power Little Endian=9.0_ppc64le
redhat Codeready Linux Builder Eus For Power Little Endian Eus=9.2_ppc64le
redhat Codeready Linux Builder For Arm64=9.0_aarch64
redhat Codeready Linux Builder For Arm64 Eus=9.2_aarch64
redhat Codeready Linux Builder For Ibm Z Systems=9.0_s390x
redhat Codeready Linux Builder For Ibm Z Systems Eus=9.2_s390x
redhat Enterprise Linux Eus=8.8
redhat Enterprise Linux Eus=9.2
redhat Enterprise Linux For Arm 64=9.0_aarch64
redhat Enterprise Linux For Arm 64 Eus=9.2_aarch64
redhat Enterprise Linux For Ibm Z Systems=8.0_s390x
redhat Enterprise Linux For Ibm Z Systems Eus=8.8_s390x
redhat Enterprise Linux For Ibm Z Systems Eus S390x=9.2
redhat Enterprise Linux For Ibm Z Systems S390x=9.2
redhat Enterprise Linux For Power Little Endian=8.0_ppc64le
redhat Enterprise Linux For Power Little Endian=9.2_ppc64le
redhat Enterprise Linux For Power Little Endian Eus=8.8_ppc64le
redhat Enterprise Linux For Power Little Endian Eus=9.2_ppc64le
redhat Enterprise Linux Server Aus=9.2
redhat Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions=9.2_ppc64le
redhat Enterprise Linux Tus=8.8
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
IBM Security Verify Governance, Identity Manager software component<=ISVG 10.0.2
IBM Security Verify Governance, Identity Manager virtual appliance component<=ISVG 10.0.2
GNU glibc>=2.36<2.36.113
GNU glibc>=2.37<2.37.38
GNU glibc>=2.38<2.38.19
All of the following
NetApp H300s Firmware
NetApp H300s
All of the following
NetApp H500s Firmware
NetApp H500s
All of the following
NetApp H700s Firmware
NetApp H700s
All of the following
NetApp H410s Firmware
NetApp H410s
All of the following
NetApp H410c Firmware
NetApp H410c
Microsoft azl3 glibc 2.38-11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/glibc to a version that resolves this vulnerability.

    Fixed in 2.28-10+deb10u1Fixed in 2.28-10+deb10u2Fixed in 2.31-13+deb11u6Fixed in 2.31-13+deb11u7Fixed in 2.36-9+deb12u3Fixed in 2.37-12
  2. Upgrade

    Upgrade ubuntu/glibc to a version that resolves this vulnerability.

    Fixed in 2.37-0ubuntu2.1
  3. Upgrade

    Upgrade ubuntu/glibc to a version that resolves this vulnerability.

    Fixed in 2.38-1ubuntu5

Event History

Aug 25, 2023
Data Sourced
via Red Hat·08:25 AM
DescriptionSeverityAffected Software
Sep 18, 2023
CVE Published
12:00 AM
CVE Published
via MITRE·04:32 PM
Data Sourced
via MITRE·04:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 18, 2023
Data Sourced
02:03 PM
Description
Jul 11, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-4527?

CVE-2023-4527 is a vulnerability found in glibc that allows for a stack read overflow in the getaddrinfo function.

2

What is the severity of CVE-2023-4527?

CVE-2023-4527 has a severity score of 8.2, indicating a high severity.

3

How does CVE-2023-4527 affect GNU glibc?

CVE-2023-4527 affects GNU glibc up to version 2.39.

4

How does CVE-2023-4527 affect Redhat Enterprise Linux?

CVE-2023-4527 affects Redhat Enterprise Linux versions 8.0 and 9.0.

5

How can CVE-2023-4527 be fixed?

Updating to a version of glibc that is not affected by CVE-2023-4527 is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203