CVE-2024-33602
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.40%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
- CVSS 3.1
- 7.4 HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-466
- Affected
- gnu/glibc · debian/debian linux · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware · netapp/h410c firmware · netapp/element software · netapp/solidfire \& hci management node · netapp/solidfire \& hci storage node · netapp/hci bootstrap os
- Source
- 3ff69d7a-14f2-4f67-a097-88dee7810d18
References
- http://www.openwall.com/lists/oss-security/2024/07/22/5Mailing List
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240524-0012/Third Party Advisory
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008Broken Link
- http://www.openwall.com/lists/oss-security/2024/07/22/5Mailing List
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240524-0012/Third Party Advisory
- https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008Broken Link
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.