VDB

RHSA-2024%3A4126

RHSA-2024%3A4126 PUBLISHED CVSS 8.800000190734863 HIGH

A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatservice-interconnect/skupper-flow-collector-rhel9@sha256:2dfbfbe8c0d129eabda2111a4901b61ac1d7e6e6424c11bf08669aef4479cac6_amd64 as a component of 9Base-Service-Interconnect-1.4service-interconnect/skupper-flow-collector-rhel9@sha256:2dfbfbe8c0d129eabda2111a4901b61ac1d7e6e6424c11bf08669aef4479cac6_amd64
Red Hatservice-interconnect/skupper-service-controller-rhel9@sha256:93ca95396c7f18bd736226d96728415364ad8327510eaff8eb18716a7f1cd5a8_amd64 as a component of 9Base-Service-Interconnect-1.4*
Red Hatservice-interconnect/skupper-site-controller-rhel9@sha256:ab50c15ee7f5bcf71160f261447634b0f68f09704ec5f0c15f034b0578f37416_amd64 as a component of 9Base-Service-Interconnect-1.4service-interconnect/skupper-site-controller-rhel9@sha256:ab50c15ee7f5bcf71160f261447634b0f68f09704ec5f0c15f034b0578f37416_amd64
Red Hatservice-interconnect/skupper-config-sync-rhel9@sha256:acec4546e82ec80f9b1c90cf43f653f44fe42a5f9b3b3e353c794cb4085c8156_amd64 as a component of 9Base-Service-Interconnect-1.4service-interconnect/skupper-config-sync-rhel9@sha256:acec4546e82ec80f9b1c90cf43f653f44fe42a5f9b3b3e353c794cb4085c8156_amd64
Red Hatservice-interconnect/skupper-operator-bundle@sha256:fa023abc1d035d287121e6d96a97fab219fe6297c0c3205b4d08ad955520efdd_amd64 as a component of 9Base-Service-Interconnect-1.4*
Red Hatservice-interconnect/skupper-router-rhel9@sha256:20cf7f29b16b5811d3161e58aeb2281c6ac6760ce3eb95e7aa491c43ac545e44_amd64 as a component of 9Base-Service-Interconnect-1.4service-interconnect/skupper-router-rhel9@sha256:20cf7f29b16b5811d3161e58aeb2281c6ac6760ce3eb95e7aa491c43ac545e44_amd64

Timeline

  • Jun 26, 2024 CVE Published
  • Apr 24, 2026 CVE Updated
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Distribution Patch
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
  • Apr 25, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›