VYPR
High severity7.5OSV Advisory· Published Dec 4, 2018· Updated Jun 17, 2026

CVE-2018-19591

CVE-2018-19591

Description

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • GNU/GlibcOSV3 versions
    cvs/ChangeLog, cvs/amigados-merge, cvs/before-thomas-posix1996, …+ 2 more
    • (no CPE)range: cvs/ChangeLog, cvs/amigados-merge, cvs/before-thomas-posix1996, …
    • cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*range: <=2.28
    • (no CPE)range: <=2.28
  • cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
  • GNU/C Libraryllm-fuzzy
    Range: <=2.28
  • GNU/libc6llm-fuzzy
    Range: <=2.28

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.