High severity7.5OSV Advisory· Published Dec 4, 2018· Updated Jun 17, 2026
CVE-2018-19591
CVE-2018-19591
Description
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- sourceware.org/bugzilla/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- www.securityfocus.com/bid/106037nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1042174nvdThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201903-09nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO7WHN52GFMC5F2I2232GFIPSSXWFV7G/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M52KE4YR3GNMHQUOS3DKAGZD5TQ5D5UH/nvd
- security.gentoo.org/glsa/201908-06nvd
- security.netapp.com/advisory/ntap-20190321-0003/nvd
- sourceware.org/git/gitweb.cginvd
- usn.ubuntu.com/4416-1/nvd
News mentions
0No linked articles in our index yet.