{"id":"CVE-2017-8804","details":"The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references","modified":"2026-08-30T14:04:17.140790Z","published":"2017-05-07T18:29:00.157Z","related":["SUSE-SU-2018:0451-1","SUSE-SU-2018:0565-1"],"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00026.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00039.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2018-02/msg00049.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/98339"},{"type":"WEB","url":"https://seclists.org/oss-sec/2017/q2/228"},{"type":"WEB","url":"https://sourceware.org/legacy-ml/libc-alpha/2017-05/msg00128.html"},{"type":"WEB","url":"https://sourceware.org/legacy-ml/libc-alpha/2017-05/msg00129.html"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2017/05/05/2"},{"type":"FIX","url":"https://bugzilla.suse.com/show_bug.cgi?id=1037559#c7"},{"type":"FIX","url":"https://sourceware.org/bugzilla/show_bug.cgi?id=21461"},{"type":"FIX","url":"https://sourceware.org/ml/libc-alpha/2017-05/msg00105.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bminor/glibc","events":[{"introduced":"db0242e3023436757bbc7c488a779e6e3343db04"},{"last_affected":"db0242e3023436757bbc7c488a779e6e3343db04"}],"database_specific":{"cpe":"cpe:2.3:a:gnu:glibc:2.25:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.25"},{"last_affected":"2.25"}],"source":"CPE_STRING"}}],"versions":["2.25","glibc-2.25"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-8804.json"}},{"ranges":[{"type":"GIT","repo":"https://sourceware.org/git/glibc.git","events":[{"introduced":"db0242e3023436757bbc7c488a779e6e3343db04"},{"last_affected":"db0242e3023436757bbc7c488a779e6e3343db04"}],"database_specific":{"cpe":"cpe:2.3:a:gnu:glibc:2.25:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.25"},{"last_affected":"2.25"}],"source":"CPE_STRING"}}],"versions":["2.25","glibc-2.25"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-8804.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}