CVE Vulnerabilities

CVE-2024-56433

Initialization of a Resource with an Insecure Default

Published: Dec 26, 2024 | Modified: Dec 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.6 LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Weakness

The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatshadow-utils-2:4.15.0-8.el10*
Red Hat Enterprise Linux 9RedHatshadow-utils-2:4.9-15.el9*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:sha256:ec961e5acfde5c1ad0a7e0e2c86a0bf56b9bc46357fa124f9db6dff1006076ab*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:sha256:dce6b0ea03379bf06664a5200af8b5f5ae3fad13cdce6d21873843f22554800b*
Red Hat Ceph Storage 7RedHatrhceph/rhceph-7-rhel9:sha256:ce213d48fbefae6b9d5f5a64b79c6ed016afcb646bf7b5742707ed31f9a464a2*
Red Hat Ceph Storage 8RedHatrhceph/rhceph-8-rhel9:sha256:08f8552a0a56a47ab606bed47b603e3d2aedaa389d4a5df4dbfa06acee85c0c0*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:sha256:b4683720677a1e45efbfd291d8b130b530642221e8a55a49e931e1b8b2c81ac3*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe*
ShadowUbuntufocal*
ShadowUbuntuoracular*
ShadowUbuntuplucky*

References