CVE-2023-4527

Modified
Published: 18 Sept 2023, 16:32
Last modified:12 May 2026, 10:12

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.11% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

18 Sept 2023, 16:32
Published
Vulnerability first disclosed
12 May 2026, 10:12
Last Modified
Vulnerability information updated

Description

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H

EPSS Trends

Current EPSS score: 0.11% Percentile: 29%

Techniques & Countermeasures

  • CWE-121Stack-based Buffer Overflow

    A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • fedoraprojectfedora

    37 | 38 | 39

  • gnuglibc

    ≥ 2.36, < 2.36.113 | ≥ 2.37, < 2.37.38 | ≥ 2.38, < 2.38.19

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph700s_firmware

    na

  • redhatcodeready_linux_builder_eus

    9.2

  • redhatcodeready_linux_builder_eus_for_power_little_endian

    9.0_ppc64le

  • redhatcodeready_linux_builder_eus_for_power_little_endian_eus

    9.2_ppc64le

  • redhatcodeready_linux_builder_for_arm64

    9.0_aarch64

  • redhatcodeready_linux_builder_for_arm64_eus

    9.2_aarch64

  • redhatcodeready_linux_builder_for_ibm_z_systems

    9.0_s390x

  • redhatcodeready_linux_builder_for_ibm_z_systems_eus

    9.2_s390x

  • redhatenterprise_linux

    8.0 | 9.0

  • redhatenterprise_linux_eus

    8.8 | 9.2

  • redhatenterprise_linux_for_arm_64

    9.0_aarch64

  • redhatenterprise_linux_for_arm_64_eus

    9.2_aarch64

  • redhatenterprise_linux_for_ibm_z_systems

    8.0_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus

    8.8_s390x

  • redhatenterprise_linux_for_ibm_z_systems_eus_s390x

    9.2

  • redhatenterprise_linux_for_ibm_z_systems_s390x

    9.2

  • redhatenterprise_linux_for_power_little_endian

    8.0_ppc64le | 9.2_ppc64le

  • redhatenterprise_linux_for_power_little_endian_eus

    8.8_ppc64le | 9.2_ppc64le

  • redhatenterprise_linux_server_aus

    9.2

  • redhatenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions

    9.2_ppc64le

  • redhatenterprise_linux_tus

    8.8

References (12)