Asymmetric denial of service In glibc
Description
nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference. This flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present in the nscd binary.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2.36-9+deb12u7 | ||
debian 11 | 2.31-13+deb11u10 | ||
debian 13 | 2.37-19 | ||
debian 14 | 2.37-19 | ||
rpm rhel7 | 0:2.17-326.el7_9.3 | ||
rpm rhel8 | 0:2.28-251.el8_10.2 | ||
rpm rhel9 | 0:2.34-100.el9_4.2 | ||
rpm rhel6 | - | - | |
rpm rhel9.0 | 0:2.34-28.el9_0.6 | ||
rpm rhel9.2 | 0:2.34-60.el9_2.14 |
1-10 of 12
10
Aliases
1. 2. 3. 4. 5.