CVE detail
CVE-2023-4806
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.3 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
16 source links · newest first
- https://cert-portal.siemens.com/productcert/html/ssa-831302.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comSep 18, 2023, 5:15 PM - https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comSep 18, 2023, 5:15 PM - https://security.netapp.com/advisory/ntap-20240125-0008/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comSep 18, 2023, 5:15 PM - https://security.gentoo.org/glsa/202310-03security.gentoo.org
No excerpt available.
Vendor Advisorysecurity.gentoo.orgSep 18, 2023, 5:15 PM - https://lists.fedoraproject.org/archives/list/[email protected]/message/NDAQWHTSVOCOZ5K6KPIWKRT3JX4RTZUR/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgSep 18, 2023, 5:15 PM - https://lists.fedoraproject.org/archives/list/[email protected]/message/DFG4P76UHHZEWQ26FWBXG76N2QLKKPZA/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgSep 18, 2023, 5:15 PM - https://lists.fedoraproject.org/archives/list/[email protected]/message/4DBUQRRPB47TC3NJOUIBVWUGFHBJAFDL/lists.fedoraproject.org
No excerpt available.
Third Party Advisorylists.fedoraproject.orgSep 18, 2023, 5:15 PM - http://www.openwall.com/lists/oss-security/2023/10/03/8www.openwall.com
No excerpt available.
Exploitwww.openwall.comSep 18, 2023, 5:15 PM - http://www.openwall.com/lists/oss-security/2023/10/03/6www.openwall.com
No excerpt available.
Exploitwww.openwall.comSep 18, 2023, 5:15 PM - http://www.openwall.com/lists/oss-security/2023/10/03/5www.openwall.com
No excerpt available.
Exploitwww.openwall.comSep 18, 2023, 5:15 PM - http://www.openwall.com/lists/oss-security/2023/10/03/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comSep 18, 2023, 5:15 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2237782bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comSep 18, 2023, 5:15 PM - https://access.redhat.com/security/cve/CVE-2023-4806access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comSep 18, 2023, 5:15 PM - https://access.redhat.com/errata/RHSA-2023:7409access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comSep 18, 2023, 5:15 PM - https://access.redhat.com/errata/RHSA-2023:5455access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comSep 18, 2023, 5:15 PM - https://access.redhat.com/errata/RHSA-2023:5453access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comSep 18, 2023, 5:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-4527CVSS 6.5 · Medium
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS res…
- CVE-2023-5633CVSS 7.8 · High
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being u…
- CVE-2023-3758CVSS 7.1 · High
A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denyi…
- CVE-2024-1488CVSS 8.0 · High
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process…
- CVE-2025-2784CVSS 7.0 · High
A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one by…
- CVE-2025-3155CVSS 7.4 · High
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents,…