PT-2026-95018 · Gnu · Gnu C Library
CVSS v3.1
5.3
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU C Library versions 2.26 through 2.44
Description
Initializing the DNS stub resolver using a
LOCALDOMAIN environment variable or an /etc/resolv.conf file containing a search list with a domain of approximately 200 characters or more causes an assertion failure that aborts the process. This occurs because the resolver truncates the search list when copying it into the fixed-size res.defdname buffer, but the subsequent consistency check uses an incorrect size and fails to handle cases where the first entry does not fit. An attacker on the local network could potentially trigger this by providing malicious search domains via DHCP or a VPN server, affecting any process that resolves names through the library.Recommendations
Update GNU C Library to a version later than 2.44.
Exploit
Fix
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu C Library