CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-33601: nscd: netgroup cache may terminate daemon on memory allocation failure

Description

nscd: netgroup cache may terminate daemon on memory allocation failure

The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or
xrealloc and these functions may terminate the process due to a memory
allocation failure resulting in a denial of service to the clients. The
flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

Classification

CVE ID: CVE-2024-33601

Affected Products

Vendor: The GNU C Library

Product: glibc

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 18.33% (scored less or equal to compared to others)

EPSS Date: 2025-03-05 (when was this score calculated)

References

https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0007
https://security.netapp.com/advisory/ntap-20240524-0014/
https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
http://www.openwall.com/lists/oss-security/2024/07/22/5

Timeline