cbcvebase.
CVE-2021-27645
published 2021-02-24

CVE-2021-27645: The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due…

low2.5CVSS 3.1
AVLACHPRLUINSUCNINAL
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianglibc< glibc 2.31-10 (bookworm)glibc 2.31-10 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
gnuglibc>= 0 < 2.31-102.31-10
gnuglibc>= 0 < 2.31-102.31-10
gnuglibc>= 0 < 2.31-102.31-10
gnuglibc>= 0 < 2.31-102.31-10
gnuglibc>= 0 < 2.27-3ubuntu1.52.27-3ubuntu1.5
gnuglibc>= 0 < 2.31-0ubuntu9.72.31-0ubuntu9.7
gnuglibc2.29 – 2.33
paloaltopan-os

CVSS provenance

nvdv3.12.5LOWCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
osv5.9MEDIUM