CVE-2024-33599
HIGHglibc 2.15-2.39 - Stack-based Buffer Overflow in nscd Netgroup Cache
Title source: llmDescription
nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a stack-based buffer overflow. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/07/22/5
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20240524-0011/
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Scores
CVSS v3
8.1
EPSS
0.0118
EPSS Percentile
79.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-121
Status
published
Products (9)
debian/debian_linux
10.0
gnu/glibc
2.15 - 2.40
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h700s_firmware
netapp/hci_bootstrap_os
The GNU C Library/glibc
2.15 - 2.40
Published
May 06, 2024
Tracked Since
Feb 18, 2026