The vendor explicitly identifies these products as affected by this CVE.
- openshift/ose-rhel-coreos-8 as a component of Red Hat OpenShift Container Platform 4
- openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, causing it to crash and leading to degraded DNS resolution for the system. There is also a remote possibility of nscd cache corruption.
- Remediation
- Fix deferred
