CVE-2023-4813: Glibc: potential use-after-free in gaih_inet()
A flaw has been identified in glibc. In an uncommon situation, the gaihinet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
Other sources
A flaw was found in glibc. In an uncommon situation, the gaihinet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
— Ubuntu
glibc is vulnerable to a denial of service, caused by a use-after-free flaw in the gaihinet function. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Glibc: potential use-after-free in gaihinet()
— Microsoft
In an uncommon situation, the gaihinet function in glibc may use memory that has already been freed, resulting in an application crash.
This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
This flaw affects glibc versions prior to 2.36.
Reference: https://sourceware.org/bugzilla/showbug.cgi?id=28931
Upstream patch: https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=1c37b8022e8763fedbb3f79c02e05c6acfe5a215
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-4813?
CVE-2023-4813 is a vulnerability found in glibc that can result in an application crash when the getaddrinfo function is called.
What is the severity of CVE-2023-4813?
The severity of CVE-2023-4813 is medium with a CVSS score of 5.9.
How does CVE-2023-4813 affect Redhat Enterprise Linux 8.0?
Redhat Enterprise Linux 8.0 is affected by CVE-2023-4813.
How do I fix CVE-2023-4813?
To fix CVE-2023-4813, update the glibc package to version 2.36 or apply the recommended fix provided by Redhat.
Where can I find more information about CVE-2023-4813?
You can find more information about CVE-2023-4813 on the CVE website and the NIST National Vulnerability Database.