CVE-2024-33601
HIGHDescription
nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Is your site exposed to CVE-2024-33601?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gnu | glibc |
| debian | debian_linux |
| netapp | h300s_firmware |
| netapp | h300s |
| netapp | h500s_firmware |
| netapp | h500s |
| netapp | h700s_firmware |
| netapp | h700s |
| netapp | h410s_firmware |
| netapp | h410s |
| netapp | h410c_firmware |
| netapp | h410c |
| netapp | h610c_firmware |
| netapp | h610c |
| netapp | h615c_firmware |
| netapp | h615c |
| netapp | h610s_firmware |
| netapp | h610s |
| netapp | hci_bootstrap_os |
| netapp | hci_compute_node |
References
Other References
Frequently Asked Questions
What is CVE-2024-33601? +
How severe is CVE-2024-33601? +
What products are affected by CVE-2024-33601? +
How do I check if I'm vulnerable to CVE-2024-33601? +
Related Vulnerabilities
In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard …
wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the …
A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted …
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated …
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted …
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction …