cbcvebase.
CVE-2024-33602
published 2024-05-06

CVE-2024-33602: nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback…

PriorityP339high7.4CVSS 3.1
AVLACHPRNUINSUCHIHAH
EPSS
0.40%
32.7th percentile
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianglibc< glibc 2.36-9+deb12u7 (bookworm)glibc 2.36-9+deb12u7 (bookworm)
gnuglibc>= 0 < 2.31-13+deb11u102.31-13+deb11u10
gnuglibc>= 0 < 2.36-9+deb12u72.36-9+deb12u7
gnuglibc>= 0 < 2.37-192.37-19
gnuglibc>= 0 < 2.37-192.37-19
gnuglibc>= 0 < 2.31-0ubuntu9.162.31-0ubuntu9.16
gnuglibc>= 0 < 2.35-0ubuntu3.82.35-0ubuntu3.8
gnuglibc>= 0 < 2.39-0ubuntu8.22.39-0ubuntu8.2
gnuglibc>= 0 < 2.23-0ubuntu11.3+esm72.23-0ubuntu11.3+esm7
gnuglibc>= 0 < 2.27-3ubuntu1.6+esm32.27-3ubuntu1.6+esm3
gnuglibc>= 2.15 < 2.402.40
msrcazl3_glibc_2.38-10_on_azure_linux_3.0
msrccbl2_glibc_2.35-7_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
paloaltopan-os
the_gnu_c_libraryglibc>= 2.15 < 2.402.40

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_msrc8.6HIGH
vendor_oracle8.6HIGH
vendor_ubuntu8.1HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.