CVE-2024-33601
Last modified
CVE-2024-33601 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Glibc | >= 2.15, < 2.40 |
| Debian | Debian Linux | 10.0 |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
| Netapp | H410c Firmware | All versions |
| Netapp | H610c Firmware | All versions |
| Netapp | H615c Firmware | All versions |
| Netapp | H610s Firmware | All versions |
| Netapp | Hci Bootstrap Os | All versions |
References
- http://www.openwall.com/lists/oss-security/2024/07/22/5Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240524-0014/Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/07/22/5Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00026.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240524-0014/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-33601?
How severe is CVE-2024-33601?
How do I fix CVE-2024-33601?
Are you affected by CVE-2024-33601?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
