CVE Vulnerabilities

CVE-2024-33602

Return of Pointer Value Outside of Expected Range

Published: May 06, 2024 | Modified: Jun 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
4 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

nscd: netgroup cache assumes NSS callback uses in-buffer strings

The Name Service Cache Daemons (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

Weakness

A function can return a pointer to memory that is outside of the buffer that the pointer is expected to reference.

Affected Software

NameVendorStart VersionEnd Version
GlibcGnu2.15 (including)2.40 (excluding)
Red Hat Enterprise Linux 7RedHatglibc-0:2.17-326.el7_9.3*
Red Hat Enterprise Linux 8RedHatglibc-0:2.28-251.el8_10.2*
Red Hat Enterprise Linux 8RedHatglibc-0:2.28-251.el8_10.2*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatglibc-0:2.28-101.el8_2.2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatglibc-0:2.28-151.el8_4.2*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatglibc-0:2.28-151.el8_4.2*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatglibc-0:2.28-151.el8_4.2*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatglibc-0:2.28-189.10.el8_6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatglibc-0:2.28-225.el8_8.11*
Red Hat Enterprise Linux 9RedHatglibc-0:2.34-100.el9_4.2*
Red Hat Enterprise Linux 9RedHatglibc-0:2.34-100.el9_4.2*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatglibc-0:2.34-28.el9_0.6*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatglibc-0:2.34-60.el9_2.14*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatglibc-0:2.28-189.10.el8_6*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-config-sync-rhel9:1.4.5-2*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-flow-collector-rhel9:1.4.5-2*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-operator-bundle:1.4.5-4*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-router-rhel9:2.4.3-4*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-service-controller-rhel9:1.4.5-2*
Service Interconnect 1.4 for RHEL 9RedHatservice-interconnect/skupper-site-controller-rhel9:1.4.5-2*
EglibcUbuntutrusty/esm*
GlibcUbuntuesm-infra/bionic*
GlibcUbuntuesm-infra/focal*
GlibcUbuntuesm-infra/xenial*
GlibcUbuntufocal*
GlibcUbuntujammy*
GlibcUbuntumantic*
GlibcUbuntunoble*

References