CVE-2018-19591

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-19591

OS impact

OSVersionStatusFixed in
arch archfixed2.29-1
debian debianbookwormfixed2.28-1
debian debianbullseyefixed2.28-1
debian debianforkyfixed2.28-1
debian debiansidfixed2.28-1
debian debiantrixiefixed2.28-1

References

Verify integrity in audit chain (admin only). AS-IS.