DescriptionIn the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs914837

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glibc (PTS)stretch2.24-11+deb9u4fixed
stretch (security)2.24-11+deb9u1fixed
bullseye, sid2.31-9fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glibcsourcejessie(not affected)
glibcsourcestretch(not affected)


[stretch] - glibc <not-affected> (Vulnerable code introduced later and not backported to stretch)
[jessie] - glibc <not-affected> (Vulnerable code introduced later and not backported to jessie)
Fixed by:;h=d527c860f5a3f0ed687bd03f0cb464612dc23408
Introduced by:;h=2180fee114b778515b3f560e5ff1e795282e60b0

