CVE Vulnerabilities

CVE-2024-56433

Initialization of a Resource with an Insecure Default

Published: Dec 26, 2024 | Modified: Dec 26, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.6 LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Ubuntu
LOW

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Weakness

The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat shadow-utils-2:4.15.0-8.el10 *
Red Hat Enterprise Linux 9 RedHat shadow-utils-2:4.9-15.el9 *
Red Hat AI Inference Server 3.2 RedHat rhaiis/vllm-cuda-rhel9:sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b *
Red Hat AI Inference Server 3.2 RedHat rhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57 *
Red Hat AI Inference Server 3.2 RedHat rhaiis/model-opt-cuda-rhel9:sha256:14e32e88f1b89f59ed34a6d712746b82a6a54c6ed4727784f18aeff853abbdc7 *
Red Hat Ceph Storage 7 RedHat rhceph/rhceph-7-rhel9:sha256:ce213d48fbefae6b9d5f5a64b79c6ed016afcb646bf7b5742707ed31f9a464a2 *
Red Hat Ceph Storage 8 RedHat rhceph/rhceph-8-rhel9:sha256:08f8552a0a56a47ab606bed47b603e3d2aedaa389d4a5df4dbfa06acee85c0c0 *
Red Hat Discovery 2 RedHat discovery/discovery-server-rhel9:sha256:97a1bb076f7f29a5f2b80c4724cb27c4e87f89c2d73a7719c44dc8c044329503 *
Red Hat Discovery 2 RedHat discovery/discovery-ui-rhel9:sha256:69cb9c84b806ee2f448bdbbcf3174855432f5caec8f31ca2a345655da4a72f57 *
Red Hat Insights proxy 1.5 RedHat insights-proxy/insights-proxy-container-rhel9:sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d *
Shadow Ubuntu focal *
Shadow Ubuntu oracular *

References