CVE-2024-33602 Affecting glibc package, versions <2.37-19


low

Snyk CVSS

      Threat Intelligence

      EPSS 0.04% (9th percentile)
    Expand this section
    Red Hat
    4 medium

    Do your applications use this vulnerable package?

    In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

    Test your applications
    • Snyk ID SNYK-DEBIANUNSTABLE-GLIBC-6673968
    • published 26 Apr 2024
    • disclosed 6 May 2024

    Introduced: 26 Apr 2024

    New CVE-2024-33602 Open this link in a new tab

    How to fix?

    Upgrade Debian:unstable glibc to version 2.37-19 or higher.

    NVD Description

    Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

    nscd: netgroup cache assumes NSS callback uses in-buffer strings

    The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd.

    This vulnerability is only present in the nscd binary.