Junglewise Threat Intelligence

CVE-2024-33599: GNU glibc nscd stack-based buffer overflow in netgroup cache

CVE-2024-33599 · Severity: high · CVSS 8.1 · Published 2024-05-06

Technologies: NetApp H410c, Debian Linux, NetApp Hci Bootstrap Os, NetApp H410s, NetApp H300s, NetApp H700s Firmware, NetApp H500s, NetApp H410s Firmware, NetApp H700s, Siemens SIMATIC S7-1500 CPU family, NetApp H300s Firmware, Gnu Glibc, NetApp H500s Firmware, NetApp H410c Firmware. Vendors: Debian, NetApp, Siemens, Gnu.

Executive brief

A vulnerability exists in the Name Service Cache Daemon (nscd), a component used in Linux systems to speed up lookups for network resources and user groups. If the system's cache becomes full, a specific type of request can cause the program to crash or potentially allow an attacker to execute unauthorized commands. This could lead to a complete service outage or a security breach on affected servers and industrial control equipment.

Technical details

A stack-based buffer overflow (CWE-121) exists in the nscd binary of glibc. The vulnerability is triggered when the nscd fixed-size cache is exhausted by client requests; a subsequent request for netgroup data leads to the overflow. While the attack vector is network-based, it carries high complexity (AC:H) as it requires the cache to be in a specific exhausted state. Successful exploitation can lead to a daemon crash (DoS) or potentially arbitrary code execution with the privileges of the nscd process. The flaw was introduced in glibc 2.15 and is fixed in version 2.40 and various backported stable releases.

Affected products

  • GNU glibc 2.15 to 2.39
  • Debian nscd binary package 10.0 (buster)
  • Siemens SIMATIC S7-1500 CPU family V3.1.5 and later

Timeline

  • 2024-04-23: disclosed: Public date listed in glibc advisory
  • 2024-05-06: advisory: NVD published date
  • 2024-07-22: patched: glibc 2.40 released with fix

References

Related threats