Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
References
| Link | Resource |
|---|---|
| https://sourceware.org/bugzilla/show_bug.cgi?id=33802 | Broken Link |
| http://www.openwall.com/lists/oss-security/2026/01/16/6 | Mailing List |
| https://sourceware.org/bugzilla/show_bug.cgi?id=33802 | Broken Link |
Configurations
History
No history.
Information
Published : 2026-01-15 22:16
Updated : 2026-01-23 19:36
NVD link : CVE-2026-0915
Mitre link : CVE-2026-0915
CVE.ORG link : CVE-2026-0915
JSON object : View
Products Affected
gnu
- glibc
CWE
CWE-908
Use of Uninitialized Resource
