GHSA-f4pv-q5f7-2h55 · Severity: high — nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's...
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Conclusion & alert: CVE-2024-33602 is rated Moderate Risk (55.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.75%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-25 | 0.63% | 0.75% | +0.12% |
| 2 | 2026-04-21 | 0.45% | 0.63% | +0.18% |
| 3 | 2026-03-02 | — | 0.45% | — |
Full EPSS history (20 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.4 | 3.1 | HIGH |
|
1.4 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-f4pv-q5f7-2h55 · Severity: high — nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2024-33602 not yet assigned priority: Debian including 1 source packages (glibc), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-33602 |
gentoo
|
high | CVE-2024-33602: 1 GLSA(s) (202405-17), 1 atom(s) (sys-libs/glibc); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2024-33602 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2024-33602 |
suse
|
medium | CVE-2024-33602 severity moderate: SUSE including 924 source package names (1.21-14.1:glibc-2.31-150300.83.1, 1.5.4-1.11.1:glibc-2.31-150300.83.1, …), 2070 product×package rows across 288 product lines (Container bci/bci-base-fips, Container bci/bci-busybox, … (288 product lines)): Fixed 1831, Known Affected 200, Known Not Affected 39. | https://www.suse.com/security/cve/CVE-2024-33602/ |
ubuntu
|
medium | CVE-2024-33602 medium priority: Ubuntu including 2 source packages (eglibc, glibc), 19 status rows across 11 suites (bionic, focal, jammy, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 7, released 6, needs-triage 3, not-affected 3. | https://ubuntu.com/security/CVE-2024-33602 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| gnu | glibc | >= 2.15, < 2.40 | cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| netapp | h300s_firmware | — | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
| netapp | h500s_firmware | — | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
| netapp | h700s_firmware | — | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
| netapp | h410s_firmware | — | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
| netapp | h410c_firmware | — | cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* |
| netapp | element_software | — | cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:* |
| netapp | solidfire_\&_hci_management_node | — | cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* |
| netapp | solidfire_\&_hci_storage_node | — | cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:* |
| netapp | hci_bootstrap_os | — | cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2024/07/22/5 | Mailing List |
| https://lists.debian.org/debian-lts-announce/2024/06/msg00026.html | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20240524-0012/ | Third Party Advisory |
| https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2024-0008 | Broken Link |
| https://cert-portal.siemens.com/productcert/html/ssa-082556.html |