[COMMITTED] advisories: Update GLIBC-SA-2026-0012 metadata
Carlos O'Donell
carlos@redhat.com
Fri Jun 19 20:35:07 GMT 2026
Update vulnerable versions in descriptive text.
---
advisories/GLIBC-SA-2026-0012 | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/advisories/GLIBC-SA-2026-0012 b/advisories/GLIBC-SA-2026-0012
index 926ca16102..22071d97a6 100644
--- a/advisories/GLIBC-SA-2026-0012
+++ b/advisories/GLIBC-SA-2026-0012
@@ -1,11 +1,11 @@
Buffer overread in ns_printrrf with corrupted RDATA field
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the
-GNU C Library version 2.2 and newer fail to validate the RDATA content
-against the RDATA length in a DNS response when processing A6, CERT, LOC,
-TKEY or TSIG records, which may allow an attacker to craft a DNS
-response, causing a target application to crash or read uninitialized
-memory.
+GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA
+content against the RDATA length in a DNS response when processing A6,
+CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a
+DNS response, causing a target application to crash or read
+uninitialized memory.
These functions are for application debugging only and hence not in the
path of code executed by the DNS resolver. Further, they have been
--
2.54.0
More information about the Libc-alpha
mailing list