CVE-2016-2225

high
Published 2017-03-24 ยท Modified 2026-05-13
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.5

Description

The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.

Predictions

Exploit likelihood
83%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2016-2225 NameCVE-2016-2225 DescriptionThe __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) ReferencesDLA-561-1โ€ฆ

CVE-2016-2225

NameCVE-2016-2225
DescriptionThe __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-561-1
Debian Bugs990648

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
uclibc (PTS)bookworm, bullseye, trixie1.0.35-1fixed
forky, sid1.0.54-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
uclibcsourcewheezy0.9.32-1+deb7u1DLA-561-1
uclibcsource(unstable)1.0.20-1unimportant990648

Notes

Just for cross-compiling, not used for actual packages
https://repo.or.cz/uclibc-ng.git/commit/6932f2282ba0578d6ca2f21eead920d6b78bc93c
https://www.openwall.com/lists/oss-security/2016/02/05/2

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
Just for cross-compiling, not used for actual packageshttps://repo.or.cz/uclibc-ng.git/commit/6932f2282ba0578d6ca2f21eead920d6b78bc93chttps://www.openwall.com/lists/oss-security/2016/02/05/2

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.0.20-1
debian debianbullseyefixed1.0.20-1
debian debianforkyfixed1.0.20-1
debian debiansidfixed1.0.20-1
debian debiantrixiefixed1.0.20-1

Application impact

VendorProductVersionsFixed
uclibc-ng_projectuclibc-ng{"endIncluding":"1.0.11"}

References

CWEs

CWE-400

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.