CVE-2023-4813: Fedoraproject Fedora

Medium severity, CVSS 5.9. EPSS: 1.9% chance of exploitation in the next 30 days.

A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.

Affected products

  • Fedoraproject Fedora: version 38 only
  • GNU Glibc: before 2.36 (fixed in 2.36)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Red Hat Enterprise Linux Eus: version 8.8 only; version 9.2 only
  • Red Hat Enterprise Linux For IBM Z Systems Eus s390x: version 9.2 only
  • Red Hat Enterprise Linux For IBM Z Systems s390x: version 9.2 only
  • Red Hat Enterprise Linux For Power Little Endian: version 9.2_ppc64le only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 9.2_ppc64le only
  • Red Hat Enterprise Linux Server Aus: version 9.2 only
  • Red Hat Enterprise Linux Server Tus: version 8.8 only

Published 2023-09-12. Last modified 2026-06-17.