CVE-2024-33602nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
CWE-466
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 2 years.
CVSS E:U
A genuine Java vulnerability in a supported product that the agent cannot reach: a coverage gap, not an out-of-domain finding.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification marked OUT-OF-SCOPE but CVE matches known CPE products |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
1 metric
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.4 | HIGH | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
CISA-ADP | Secondary | published |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update January 2025 ↗ | CPU | 2025-Q1 | Oracle Communications / Automated Test Suite (glibc) (9.0.0.0.0-9.0.2.0.0) |
| Oracle Critical Patch Update October 2024 ↗ | CPU | 2024-Q4 | Oracle Communications / Alarms, KPI, and Measurements (glibc) (23.4.0-23.4.6) Oracle Communications / Configuration (glibc) (23.4.0, 24.1.0, 24.2.0) Oracle Communications / Management Service (glibc) (23.4.0-23.4.5) Oracle Communications / Mediation Engine (glibc) (5.1, 5.2) Oracle Communications / Platform (glibc) (9.1.1.8.0) Oracle Communications / Routing (glibc) (9.1.0, 9.2.0, 9.3.0) Oracle Communications / Routing (glibc) (9.1.5) Oracle Communications / System (glibc) (4.1.0, 4.2.0) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Communications | Alarms, KPI, and Measurements (glibc) | 23.4.0-23.4.6 | |
| Oracle Communications | Automated Test Suite (glibc) | 9.0.0.0.0-9.0.2.0.0 | |
| Oracle Communications | Configuration (glibc) | 23.4.0, 24.1.0, 24.2.0 | 23.4.0 · 24.1.0 · 24.2.0 |
| Oracle Communications | Management Service (glibc) | 23.4.0-23.4.5 | |
| Oracle Communications | Mediation Engine (glibc) | 5.1, 5.2 | 5.1 · 5.2 |
| Oracle Communications | Platform (glibc) | 9.1.1.8.0 | 9.1.1.8.0 |
| Oracle Communications | Routing (glibc) | 9.1.0, 9.2.0, 9.3.0 | 9.1.0 · 9.1.5 · 9.2.0 · 9.3.0 |
| Oracle Communications | System (glibc) | 4.1.0, 4.2.0 | 4.1.0 · 4.2.0 |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | debian | debian linux | generic | 10.0 |
| nvd | gnu | glibc | generic | ≥ 2.15 and < 2.40 |
| nvd | netapp | element software | generic | any version |
| nvd | netapp | h300s firmware | generic | any version |
| nvd | netapp | h410c firmware | generic | any version |
| nvd | netapp | h410s firmware | generic | any version |
| nvd | netapp | h500s firmware | generic | any version |
| nvd | netapp | h700s firmware | generic | any version |
| nvd | netapp | hci bootstrap os | generic | any version |
| nvd | netapp | solidfire \& hci management node | generic | any version |
| nvd | netapp | solidfire \& hci storage node | generic | any version |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/07/22/5 | Mailing List |
| https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html | Mailing List, Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20240524-0012/ | Third Party Advisory |
| https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008 | Broken Link |
| https://cert-portal.siemens.com/productcert/html/ssa-082556.html |
| Published | 2024-05-06 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |