Impact
A stack overflow occurs in the nscd daemon of the GNU C Library when a DNS query from a malicious DNS server. The overflow corrupts the thread stack, causing nscd to crash or potentially leads to degraded DNS resolution performance but does not provide an attacker with code execution or denial of service capabilities.
Affected Systems
Systems running glibc 2.3.4 or newer with the nscd service enabled and using an untrusted DNS server are affected. The vulnerability only manifests when the DNS server can supply records large enough to exceed the stack allocation used by nscd; typical default installations run nscd as an isolated user, so direct privilege escalation is limited.
Risk and Exploitability
The vulnerability is currently rated with a CVSS score of 4.2, which corresponds to Medium severity. The EPSS score of < 1% indicates a very low probability of exploitation. The issue is not listed in the CISA KEV catalog. Because the crash occurs in a user‑level service and the service runs with limited privileges, the attack surface for privilege escalation is low, but sustained crashes could impair name resolution reliability.
OpenCVE Enrichment