CVE-2026-0915

Published: January 18, 2026Last modified: January 20, 2026

Description

Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSglibcFixed (2.37.0-r20)
25 LTSglibcFixed (2.39.0-r5)
StreamglibcFixed (2.39.0-r6)
Hardened Containers23 LTSglibcFixed (2.37.0-r20)
25 LTSglibcFixed (2.39.0-r5)
StreamglibcFixed (2.39.0-r6)

References

ON THIS PAGE