nscd: netgroup cache may terminate daemon on memory allocation failure

The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or
xrealloc and these functions may terminate the process due to a memory
allocation failure resulting in a denial of service to the clients. The
flaw was introduced in glibc 2.15 when the cache was added to nscd.

This vulnerability is only present in the nscd binary.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
H300s Firmware Subscribe
H410c Firmware Subscribe
H410s Firmware Subscribe
H500s Firmware Subscribe
H610c Firmware Subscribe
H610s Firmware Subscribe
H615c Firmware Subscribe
H700s Firmware Subscribe
Hci Bootstrap Os Subscribe
Hci Compute Node Subscribe
Enterprise Linux Subscribe
Rhel Aus Subscribe
Rhel E4s Subscribe
Rhel Eus Subscribe
Rhel Tus Subscribe
Rhev Hypervisor Subscribe
Service Interconnect Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3850-1 glibc security update
Debian DSA Debian DSA DSA-5678-1 glibc security update
Ubuntu USN Ubuntu USN USN-6804-1 GNU C Library vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 01 Aug 2025 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Netapp h610c Firmware
Netapp hci Compute Node
CPEs cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*
Vendors & Products Netapp h610c Firmware
Netapp hci Compute Node

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00054}

epss

{'score': 0.00067}


Wed, 18 Jun 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Debian
Debian debian Linux
Netapp
Netapp h300s
Netapp h300s Firmware
Netapp h410c
Netapp h410c Firmware
Netapp h410s
Netapp h410s Firmware
Netapp h500s
Netapp h500s Firmware
Netapp h610c
Netapp h610s
Netapp h610s Firmware
Netapp h615c
Netapp h615c Firmware
Netapp h700s
Netapp h700s Firmware
Netapp hci Bootstrap Os
CPEs cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h615c:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*
Vendors & Products Debian
Debian debian Linux
Netapp
Netapp h300s
Netapp h300s Firmware
Netapp h410c
Netapp h410c Firmware
Netapp h410s
Netapp h410s Firmware
Netapp h500s
Netapp h500s Firmware
Netapp h610c
Netapp h610s
Netapp h610s Firmware
Netapp h615c
Netapp h615c Firmware
Netapp h700s
Netapp h700s Firmware
Netapp hci Bootstrap Os

Tue, 18 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Fri, 21 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 4.0, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Thu, 13 Feb 2025 18:00:00 +0000

Type Values Removed Values Added
Description nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary. nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: glibc

Published:

Updated: 2025-03-18T13:55:13.348Z

Reserved: 2024-04-24T20:35:08.340Z

Link: CVE-2024-33601

cve-icon Vulnrichment

Updated: 2024-08-02T02:36:04.342Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-06T20:15:11.603

Modified: 2025-08-01T01:56:26.467

Link: CVE-2024-33601

cve-icon Redhat

Severity : Low

Publid Date: 2024-04-24T00:00:00Z

Links: CVE-2024-33601 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses