Impact
An assertion failure in glibc’s DNS stub resolver occurs when a search list containing a domain of roughly 200 characters or more is loaded, leading to a process abort. The flaw arises from truncating the search list into a fixed-size buffer and performing a consistency check against the wrong size, causing valid configurations to fail. This results in denial of service for any application that performs name resolution via glibc, including long‑running services that reload /etc/resolv.conf after changes. The weakness is represented by CWE-1025 and CWE-617.
Affected Systems
The GNU C Library glibc versions between 2.26 and 2.44 on Linux distributions are affected. All systems employing these library versions for DNS resolution, such as standard user applications and system daemons that resolve names, are at risk. The criteria for a problem include any glibc 2.26–2.44 compiled with the default resolver, regardless of the operating system vendor.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity, while the EPSS score is below 1 %, showing a very low probability of active exploitation. It is not listed in the CISA KEV catalog. An attacker would need to supply a long search domain via infrastructure elements that write to /etc/resolv.conf—such as DHCP or a VPN server—without elevated privileges. The required attack vector is therefore local network. The impact is a denial of service that terminates the calling process, which could affect critical services.
OpenCVE Enrichment