{
  "cves": [
    "CVE-2023-4813",
    "CVE-2023-4806",
    "CVE-2023-4527",
    "CVE-2023-4911"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.28-225.0.4.6]\n- CVE-2023-4527: Stack read overflow in getaddrinfo in no-aaa mode.\n- CVE-2203-4806: potential use-after-free in getaddrinfo.\n- CVE-2023-4813: potential use-after-free in gaih_inet (RHEL-2435).\n- CVE-2023-4813: work around RHEL-8 limitation in test (RHEL-2435).\n  Reviewed by: Jose E. Marchesi jose.marchesi@oracle.com\n\n[2.28-225.0.4]\n- CVE-2023-4911: tunables: Terminate immediately if end of input is reached\n  Reviewed by: Jose E. Marchesi jose.marchesi@oracle.com\n\n[2.28-225.0.3]\n- OraBug 35317410 Glibc tunable to disable huge pages on pthread_create stacks\n- Created tunable glibc.pthread.stack_hugetlb to control when hugepages\n  can be used for stack allocation.\n- In case THP are enabled and glibc.pthread.stack_hugetlb is set to\n  0, glibc will madvise the kernel not to use allow hugepages for stack\n  allocations.\n  Reviewed-by: Jose E. Marchesi jose.marchesi@oracle.com\n\n[2.28-225.0.2]\n- OraBug: 35268809 Fixed initialization of VDSO for tcache_key_initialize\n  Reviewed-by: Jose E. Marchesi jose.marchesi@oracle.com\n\n[2.28-225.0.1]\n- Merge of Oracle patches for ol8u8 beta\n  Reviewed-by: Jose E. Marchesi jose.marchesi@oracle.com\n\n[2.28-225]\n- Enforce a specififc internal ordering for tunables (#2154914)",
  "id": "ELSA-2023-12872",
  "ovalId": "oval:com.oracle.elsa:def:202312872",
  "source": "oracle_linux",
  "title": "ELSA-2023-12872:  glibc security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2023-12872.html"
}