CVE-2024-33601: nscd: netgroup cache may terminate daemon on memory allocation failure
glibc is vulnerable to a denial of service, caused by a memory allocation failure when the Name Service Cache Daemon's (nscd) netgroup cache uses the xmalloc or xrealloc functions. A local attacker could exploit this vulnerability to terminate the daemon.
Other sources
nscd: netgroup cache may terminate daemon on memory allocation failure
— Microsoft
The netgroup cache uses xmalloc/xrealloc and may terminate the process due to a memory allocation failure.
Reference: https://sourceware.org/bugzilla/showbug.cgi?id=31679
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/glibcto a version that resolves this vulnerability.Fixed in 2.31-13+deb11u11Fixed in 2.31-13+deb11u10Fixed in 2.36-9+deb12u8Fixed in 2.36-9+deb12u7Fixed in 2.40-2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33601?
CVE-2024-33601 has been classified as a denial of service vulnerability that could impact system availability.
How do I fix CVE-2024-33601?
To mitigate CVE-2024-33601, upgrade the affected glibc package to a version that addresses the vulnerability.
Which products are affected by CVE-2024-33601?
CVE-2024-33601 affects IBM QRadar Network Packet Capture and F5 Traffix SDC among other glibc implementations.
Can CVE-2024-33601 be exploited remotely?
CVE-2024-33601 requires local access for exploitation and primarily targets the Name Service Cache Daemon.
What could an attacker achieve by exploiting CVE-2024-33601?
An attacker exploiting CVE-2024-33601 could cause the Name Service Cache Daemon to terminate, leading to denial of service.