CVE-2024-33602
published 2024-05-06CVE-2024-33602: nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback…
PriorityP339high7.4CVSS 3.1
AVLACHPRNUINSUCHIHAH
EPSS
0.40%
32.7th percentile
nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory
when the NSS callback does not store all strings in the provided buffer.
The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.36-9+deb12u7 (bookworm) | glibc 2.36-9+deb12u7 (bookworm) |
| gnu | glibc | >= 0 < 2.31-13+deb11u10 | 2.31-13+deb11u10 |
| gnu | glibc | >= 0 < 2.36-9+deb12u7 | 2.36-9+deb12u7 |
| gnu | glibc | >= 0 < 2.37-19 | 2.37-19 |
| gnu | glibc | >= 0 < 2.37-19 | 2.37-19 |
| gnu | glibc | >= 0 < 2.31-0ubuntu9.16 | 2.31-0ubuntu9.16 |
| gnu | glibc | >= 0 < 2.35-0ubuntu3.8 | 2.35-0ubuntu3.8 |
| gnu | glibc | >= 0 < 2.39-0ubuntu8.2 | 2.39-0ubuntu8.2 |
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm7 | 2.23-0ubuntu11.3+esm7 |
| gnu | glibc | >= 0 < 2.27-3ubuntu1.6+esm3 | 2.27-3ubuntu1.6+esm3 |
| gnu | glibc | >= 2.15 < 2.40 | 2.40 |
| msrc | azl3_glibc_2.38-10_on_azure_linux_3.0 | — | — |
| msrc | cbl2_glibc_2.35-7_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
| the_gnu_c_library | glibc | >= 2.15 < 2.40 | 2.40 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_msrc8.6HIGH
vendor_oracle8.6HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0005 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2026-04-08·CVSS 7.5
CVE-2022-32149 [HIGH] PAN-SA-2026-0005 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2026-0005 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2022-32149 This CVE is fixed in Openconfig plugin PAN-OS 11.0.6, 11.1.8, 11.2.3-h2, 11.2.4 and all later versions of Openconfig plugin PAN-OS CVE-2024-33599 This CVE is fixed in PAN-OS versions 10.1.15, 10.2.15, 11.1.11, 11.2.7, and all later versions. CVE-2024-33600 This CVE is fixed in PAN-OS versions 10.1.15, 10.2.15, 11.1.11, 11.2.7, and all later versions. CVE-2024-33601 This CVE is fixed in PAN-OS versions 10.1.15, 10.2.15, 11.1.1
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite (glibc) — CVE-2024-33602
vendor_oracle·2025-01-15·CVSS 7.3
CVE-2024-33602 [HIGH] Oracle Oracle Communications Risk Matrix: Automated Test Suite (glibc) — CVE-2024-33602
Oracle Oracle Communications Risk Matrix: Automated Test Suite (glibc) vulnerability
CVE: CVE-2024-33602
CVSS: 7.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Management Service (glibc) — CVE-2024-33602
vendor_oracle·2024-10-15·CVSS 8.6
CVE-2024-33602 [HIGH] Oracle Oracle Communications Risk Matrix: Management Service (glibc) — CVE-2024-33602
Oracle Oracle Communications Risk Matrix: Management Service (glibc) vulnerability
CVE: CVE-2024-33602
CVSS: 8.6
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Ubuntu
GNU C Library vulnerabilities
vendor_ubuntu·2024-05-31·CVSS 8.1
CVE-2024-33601 [HIGH] GNU C Library vulnerabilities
Title: GNU C Library vulnerabilities
Summary: Several security issues were fixed in GNU C Library.
It was discovered that GNU C Library nscd daemon contained a stack-based buffer
overflow. A local attacker could use this to cause a denial of service
(system crash). (CVE-2024-33599)
It was discovered that GNU C Library nscd daemon did not properly check the
cache content, leading to a null pointer dereference vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2024-33600)
It was discovered that GNU C Library nscd daemon did not properly validate
memory allocation in certain situations, leading to a null pointer dereference
vulnerability. A local attacker could use this to cause a denial of service
(system crash). (CVE-2024-33601)
It was disc
Microsoft
nscd: netgroup cache assumes NSS callback uses in-buffer strings
vendor_msrc·2024-05-14·CVSS 8.6
CVE-2024-33602 [HIGH] CWE-466 nscd: netgroup cache assumes NSS callback uses in-buffer strings
nscd: netgroup cache assumes NSS callback uses in-buffer strings
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
glibc: glibc
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: http
Red Hat
glibc: netgroup cache assumes NSS callback uses in-buffer strings
vendor_redhat·2024-04-24·CVSS 7.4
CVE-2024-33602 [HIGH] CWE-703 glibc: netgroup cache assumes NSS callback uses in-buffer strings
glibc: netgroup cache assumes NSS callback uses in-buffer strings
nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory
when the NSS callback does not store all strings in the provided buffer.
The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.
Statement: The identified flaw in the glibc netgroup cache, while significant in its potential to cause memory corruption and crashes, may be categorized as a low severity
Debian
CVE-2024-33602: glibc - nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Servi...
vendor_debian·2024·CVSS 7.4
CVE-2024-33602 [HIGH] CVE-2024-33602: glibc - nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Servi...
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Scope: local
bookworm: resolved (fixed in 2.36-9+deb12u7)
bullseye: resolved (fixed in 2.31-13+deb11u10)
forky: resolved (fixed in 2.37-19)
sid: resolved (fixed in 2.37-19)
trixie: resolved (fixed in 2.37-19)
OSV
glibc vulnerabilities
osv·2024-05-31·CVSS 8.1
CVE-2024-33599 [HIGH] glibc vulnerabilities
glibc vulnerabilities
It was discovered that GNU C Library nscd daemon contained a stack-based buffer
overflow. A local attacker could use this to cause a denial of service
(system crash). (CVE-2024-33599)
It was discovered that GNU C Library nscd daemon did not properly check the
cache content, leading to a null pointer dereference vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2024-33600)
It was discovered that GNU C Library nscd daemon did not properly validate
memory allocation in certain situations, leading to a null pointer dereference
vulnerability. A local attacker could use this to cause a denial of service
(system crash). (CVE-2024-33601)
It was discovered that GNU C Library nscd daemon did not properly handle memory
allocatio
OSV
CVE-2024-33602: nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS
osv·2024-05-06·CVSS 7.4
CVE-2024-33602 [HIGH] CVE-2024-33602: nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
GHSA
GHSA-f4pv-q5f7-2h55: nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory
when the NS
ghsa_unreviewed·2024-05-06
CVE-2024-33602 [HIGH] CWE-466 GHSA-f4pv-q5f7-2h55: nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory
when the NS
nscd: netgroup cache assumes NSS callback uses in-buffer strings
The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory
when the NSS callback does not store all strings in the provided buffer.
The flaw was introduced in glibc 2.15 when the cache was added to nscd.
This vulnerability is only present in the nscd binary.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/07/22/5https://lists.debian.org/debian-lts-announce/2024/06/msg00026.htmlhttps://security.netapp.com/advisory/ntap-20240524-0012/https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008http://www.openwall.com/lists/oss-security/2024/07/22/5https://lists.debian.org/debian-lts-announce/2024/06/msg00026.htmlhttps://security.netapp.com/advisory/ntap-20240524-0012/https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008https://cert-portal.siemens.com/productcert/html/ssa-082556.html
2024-05-06
Published