CVE-2023-5156: Glibc: dos due to memory leak in getaddrinfo.c
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
Other sources
Glibc: dos due to memory leak in getaddrinfo.c
— Microsoft
GNU C Library (glibc) is vulnerable to a denial of service, caused by a memory leak in getaddrinfo.c. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
The fix for CVE-2023-4806 in upstream, introduces a memory leak in getaddrinfo.c which could lead to a Denial-of-Service.
https://sourceware.org/bugzilla/showbug.cgi?id=30884 https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=ec6b95c3303c700eb89eebeda2d7264cc184a796
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-5156?
CVE-2023-5156 is a vulnerability in the GNU C Library that can cause a memory leak and application crashes.
What is the severity of CVE-2023-5156?
CVE-2023-5156 has a severity rating of high (7.5).
Which software is affected by CVE-2023-5156?
The GNU C Library version up to 2.39, GNU glibc version up to 2.39, Redhat Enterprise Linux 8.0, and Redhat Enterprise Linux 9.0 are affected by CVE-2023-5156.
How can CVE-2023-5156 be exploited?
CVE-2023-5156 can be exploited by an attacker to cause a memory leak, potentially leading to application crashes.
Are there any fixes available for CVE-2023-5156?
Yes, a fix is available for CVE-2023-5156. Update to GNU C Library version 2.39 or newer.