Updated: 2025-08-20 02:35:31.747901
Description:
nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | NONE | 0.0 |
| CVSS Version 3.x | MEDIUM | 5.3 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| AlmaLinux 9.2 ESU | glibc | 2.34 | 5.3 | MEDIUM | Released | CLSA-2024:1718897210 | 2024-06-20 14:21:27 | |
| CentOS 6 ELS | glibc | 2.12 | 5.3 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity | |
| CentOS 7 ELS | glibc | 2.17 | 5.3 | MEDIUM | Released | CLSA-2024:1720027216 | 2024-07-19 04:52:17 | |
| CentOS 8.4 ELS | glibc | 2.28 | 5.3 | MEDIUM | Released | CLSA-2024:1718898112 | 2024-06-20 14:21:26 | |
| CentOS 8.5 ELS | glibc | 2.28 | 5.3 | MEDIUM | Released | CLSA-2024:1718794810 | 2024-06-19 10:11:01 | |
| CentOS Stream 8 ELS | glibc | 2.28 | 5.3 | MEDIUM | Released | CLSA-2025:1750692029 | 2025-06-24 00:46:36 | |
| CloudLinux 6 ELS | glibc | 2.12 | 5.3 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity | |
| Oracle Linux 6 ELS | glibc | 2.12 | 5.3 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity | |
| Ubuntu 16.04 ELS | glibc | 2.23-0 | 5.3 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity | |
| Ubuntu 18.04 ELS | glibc | 2.27-3 | 5.3 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity |