SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-33601

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial…

HIGH 7.3EPSS 1.07%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS 3.1
7.3 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
1.07% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-617
Affected
gnu/glibc · debian/debian linux · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware · netapp/h410c firmware · netapp/h610c firmware · netapp/h615c firmware · netapp/h610s firmware · netapp/hci bootstrap os
Source
3ff69d7a-14f2-4f67-a097-88dee7810d18

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.