Microsoft Security Response Center guidance
CBL-Mariner Releases
Vendor-listed releases
- 2.35-7
Vulnerability intelligence
CVE-2024-33602 and is rated High severity with a CVSS score of 7.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.