CVE-2024-33599

HIGH

glibc 2.15-2.39 - Stack-based Buffer Overflow in nscd Netgroup Cache

Title source: llm
STIX 2.1

Description

nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

Scores

CVSS v3 8.1
EPSS 0.0118
EPSS Percentile 79.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-121
Status published
Products (9)
debian/debian_linux 10.0
gnu/glibc 2.15 - 2.40
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
netapp/hci_bootstrap_os
The GNU C Library/glibc 2.15 - 2.40
Published May 06, 2024
Tracked Since Feb 18, 2026