In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "0.9.33.2"
}
],
"cpes": [
"cpe:2.3:a:uclibc:uclibc:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"vendor_product": "uclibc:uclibc"
}
]
}{
"cpe": "cpe:2.3:a:uclibc-ng_project:uclibc-ng:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.0.39"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-09T00:37:45Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"149264702995849926995880357077148658418",
"243810231544876742984716147609756610546",
"187030675381736448097324690676783753625",
"100290982701279520762322895167055908560",
"254510051435418387231807586264706432803",
"127470599868015528932188807542183778315",
"238947607400550915323449413440525444659",
"100291630674831964903902157310892998",
"151454825748915532144619970068739494951",
"89856833502807635002347470409707494480",
"148312366988786653925409142798107704914",
"339618317688292319097571634859286458989",
"33363081068604607857297487112370033761",
"279277696107889254542476767238182568323",
"8014272486930206910113337858133153610",
"67404679295335727849053402728486910846",
"39664672908463604438436562535780125086",
"74344633561521975023763775821125317541",
"221091041025799427006518368187122880931",
"307121273801650420540320388845313791754",
"125598997618452317981920348047648707664",
"21760855911259382741492069268857317211",
"293885711760885308786630919328611396419",
"215376830079803944236967906711375132863",
"280789395264276232750830863600257661405",
"178219953907381805852041282970328377271",
"242032130722139442784584669633065954461",
"149298575035780289452995437699480611392",
"133481329120677515855056248096345088620",
"167874028530862599751312015329974450094",
"193298813581817783774239728871110003957",
"311424175083350137278754627965055219714",
"207071184630088015915361978077643763745",
"35112011265620622621068167055770592639",
"74456878702499903498546084175784394791",
"32208519443934144979955140749924375756",
"258172524578157566106918639407807282432",
"257697376243251966081591258945331191205",
"148840428707586260763930967901346675651"
]
},
"signature_version": "v1",
"source": "https://github.com/wbx-github/uclibc-ng/commit/0f822af0445e5348ce7b7bd8ce1204244f31d174",
"id": "CVE-2021-43523-13627d42",
"target": {
"file": "libc/inet/resolv.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2922.0,
"function_hash": "142910486240576585748756844269932716179"
},
"signature_version": "v1",
"source": "https://github.com/wbx-github/uclibc-ng/commit/0f822af0445e5348ce7b7bd8ce1204244f31d174",
"id": "CVE-2021-43523-95c3f977",
"target": {
"function": "gethostbyaddr_r",
"file": "libc/inet/resolv.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 6923.0,
"function_hash": "162191713996631590485357856097300099751"
},
"signature_version": "v1",
"source": "https://github.com/wbx-github/uclibc-ng/commit/0f822af0445e5348ce7b7bd8ce1204244f31d174",
"id": "CVE-2021-43523-e3aa6a0d",
"target": {
"function": "__dns_lookup",
"file": "libc/inet/resolv.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43523.json"