CVE-2024-33600
MEDIUMglibc 2.15-2.39 - Null Pointer Dereference in nscd Netgroup Cache Handling
Title source: llmDescription
nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
References (5)
Core 5
Core References
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/07/22/5
Mailing List, Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html
Third Party Advisory
https://security.netapp.com/advisory/ntap-20240524-0013/
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-082556.html
Scores
CVSS v3
5.9
EPSS
0.0051
EPSS Percentile
66.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-476
Status
published
Products (13)
debian/debian_linux
10.0
gnu/glibc
2.15 - 2.40
netapp/active_iq_unified_manager
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h610c_firmware
netapp/h610s_firmware
netapp/h615c_firmware
... and 3 more
Published
May 06, 2024
Tracked Since
Feb 18, 2026