CVE Vulnerabilities

CVE-2024-33600

NULL Pointer Dereference

Published: May 06, 2024 | Modified: Jun 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

nscd: Null pointer crashes after notfound response

If the Name Service Cache Daemons (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
GlibcGnu2.15 (including)2.40 (excluding)
Red Hat Enterprise Linux 7RedHatglibc-0:2.17-326.el7_9.3*
Red Hat Enterprise Linux 8RedHatglibc-0:2.28-251.el8_10.2*
Red Hat Enterprise Linux 8RedHatglibc-0:2.28-251.el8_10.2*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatglibc-0:2.28-101.el8_2.2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatglibc-0:2.28-151.el8_4.2*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatglibc-0:2.28-151.el8_4.2*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatglibc-0:2.28-151.el8_4.2*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatglibc-0:2.28-189.10.el8_6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatglibc-0:2.28-225.el8_8.11*
Red Hat Enterprise Linux 9RedHatglibc-0:2.34-100.el9_4.2*
Red Hat Enterprise Linux 9RedHatglibc-0:2.34-100.el9_4.2*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatglibc-0:2.34-28.el9_0.6*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatglibc-0:2.34-60.el9_2.14*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatglibc-0:2.28-189.10.el8_6*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-config-sync-rhel9:1.4.5-2*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-flow-collector-rhel9:1.4.5-2*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-operator-bundle:1.4.5-4*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-router-rhel9:2.4.3-4*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-service-controller-rhel9:1.4.5-2*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-site-controller-rhel9:1.4.5-2*
EglibcUbuntutrusty/esm*
GlibcUbuntuesm-infra/bionic*
GlibcUbuntuesm-infra/focal*
GlibcUbuntuesm-infra/xenial*
GlibcUbuntufocal*
GlibcUbuntujammy*
GlibcUbuntumantic*
GlibcUbuntunoble*

Potential Mitigations

References