Updated: 2025-08-20 01:54:56.162198
Description:
nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a denial of service to the clients. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | NONE | 0.0 |
| CVSS Version 3.x | MEDIUM | 4.0 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| AlmaLinux 9.2 ESU | glibc | 2.34 | 4.0 | MEDIUM | Released | CLSA-2024:1718897210 | 2024-06-20 14:21:25 | |
| CentOS 6 ELS | glibc | 2.12 | 4.0 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity | |
| CentOS 7 ELS | glibc | 2.17 | 4.0 | MEDIUM | Released | CLSA-2024:1720027216 | 2024-07-19 04:52:14 | |
| CentOS 8.4 ELS | glibc | 2.28 | 4.0 | MEDIUM | Released | CLSA-2024:1718898112 | 2024-06-20 14:21:24 | |
| CentOS 8.5 ELS | glibc | 2.28 | 4.0 | MEDIUM | Released | CLSA-2024:1718794810 | 2024-06-19 10:10:58 | |
| CentOS Stream 8 ELS | glibc | 2.28 | 4.0 | MEDIUM | Released | CLSA-2025:1750692029 | 2025-06-24 00:46:35 | |
| CloudLinux 6 ELS | glibc | 2.12 | 4.0 | MEDIUM | Ignored | 2024-05-24 14:19:13 | Ignored due to low severity | |
| Oracle Linux 6 ELS | glibc | 2.12 | 4.0 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity | |
| Ubuntu 16.04 ELS | glibc | 2.23-0 | 4.0 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity | |
| Ubuntu 18.04 ELS | glibc | 2.27-3 | 4.0 | MEDIUM | Ignored | 2024-05-24 14:19:14 | Ignored due to low severity |