HIGH · 7.3

CVE-2024-33601

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due...

Vulnerability Description

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

CVSS Score

7.3

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
GnuGlibc>= 2.15, < 2.40
DebianDebian Linux10.0
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH410S Firmware-
NetappH410S-
NetappH410C Firmware-
NetappH410C-
NetappH610C Firmware-
NetappH610C-
NetappH615C Firmware-
NetappH615C-
NetappH610S Firmware-
NetappH610S-
NetappHci Bootstrap Os-
NetappHci Compute Node-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-33601?

CVE-2024-33601 is a vulnerability with a CVSS score of 7.3 (HIGH). nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due...

How severe is CVE-2024-33601?

CVE-2024-33601 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-33601?

Check the references section above for vendor advisories and patch information. Affected products include: Gnu Glibc, Debian Debian Linux, Netapp H300S Firmware, Netapp H300S, Netapp H500S Firmware.