Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver.
References
| Link | Resource |
|---|---|
| https://sourceware.org/bugzilla/show_bug.cgi?id=33802 | Broken Link |
| http://www.openwall.com/lists/oss-security/2026/01/16/6 | Mailing List |
| https://sourceware.org/bugzilla/show_bug.cgi?id=33802 | Broken Link |
Configurations
History
23 Jan 2026, 19:36
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* | |
| First Time |
Gnu
Gnu glibc |
|
| References | () https://sourceware.org/bugzilla/show_bug.cgi?id=33802 - Broken Link | |
| References | () http://www.openwall.com/lists/oss-security/2026/01/16/6 - Mailing List |
20 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://sourceware.org/bugzilla/show_bug.cgi?id=33802 - |
16 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
15 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-15 22:16
Updated : 2026-01-23 19:36
NVD link : CVE-2026-0915
Mitre link : CVE-2026-0915
CVE.ORG link : CVE-2026-0915
JSON object : View
Products Affected
gnu
- glibc
CWE
CWE-908
Use of Uninitialized Resource
