CVE-2024-33602

NameCVE-2024-33602
Descriptionnscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3850-1, DSA-5678-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glibc (PTS)bullseye (security), bullseye2.31-13+deb11u10fixed
bookworm, bookworm (security)2.36-9+deb12u7fixed
trixie2.39-4fixed
sid2.39-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glibcsourcebuster2.28-10+deb10u4DLA-3850-1
glibcsourcebullseye2.31-13+deb11u10DSA-5678-1
glibcsourcebookworm2.36-9+deb12u7DSA-5678-1
glibcsource(unstable)2.37-19

Notes

https://sourceware.org/bugzilla/show_bug.cgi?id=31680
https://inbox.sourceware.org/libc-alpha/cover.1713974801.git.fweimer@redhat.com/
https://www.openwall.com/lists/oss-security/2024/04/24/2
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008
Fixed by: https://sourceware.org/git?p=glibc.git;a=commit;h=c04a21e050d64a1193a6daab872bca2528bda44b

Search for package or bug name: Reporting problems