VDB
RHSA-2024%3A4126
RHSA-2024%3A4126
PUBLISHED
CVSS 8.800000190734863 HIGH
A flaw was found in the glibc netgroup cache. The buffer-resizing code in addgetnetgrentX assumes that all string pointers point into the supplied buffer. This can potentially lead to memory corruption and cause a crash.
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | service-interconnect/skupper-flow-collector-rhel9@sha256:2dfbfbe8c0d129eabda2111a4901b61ac1d7e6e6424c11bf08669aef4479cac6_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-flow-collector-rhel9@sha256:2dfbfbe8c0d129eabda2111a4901b61ac1d7e6e6424c11bf08669aef4479cac6_amd64 |
| Red Hat | service-interconnect/skupper-service-controller-rhel9@sha256:93ca95396c7f18bd736226d96728415364ad8327510eaff8eb18716a7f1cd5a8_amd64 as a component of 9Base-Service-Interconnect-1.4 | * |
| Red Hat | service-interconnect/skupper-site-controller-rhel9@sha256:ab50c15ee7f5bcf71160f261447634b0f68f09704ec5f0c15f034b0578f37416_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-site-controller-rhel9@sha256:ab50c15ee7f5bcf71160f261447634b0f68f09704ec5f0c15f034b0578f37416_amd64 |
| Red Hat | service-interconnect/skupper-config-sync-rhel9@sha256:acec4546e82ec80f9b1c90cf43f653f44fe42a5f9b3b3e353c794cb4085c8156_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-config-sync-rhel9@sha256:acec4546e82ec80f9b1c90cf43f653f44fe42a5f9b3b3e353c794cb4085c8156_amd64 |
| Red Hat | service-interconnect/skupper-operator-bundle@sha256:fa023abc1d035d287121e6d96a97fab219fe6297c0c3205b4d08ad955520efdd_amd64 as a component of 9Base-Service-Interconnect-1.4 | * |
| Red Hat | service-interconnect/skupper-router-rhel9@sha256:20cf7f29b16b5811d3161e58aeb2281c6ac6760ce3eb95e7aa491c43ac545e44_amd64 as a component of 9Base-Service-Interconnect-1.4 | service-interconnect/skupper-router-rhel9@sha256:20cf7f29b16b5811d3161e58aeb2281c6ac6760ce3eb95e7aa491c43ac545e44_amd64 |
Timeline
- Jun 26, 2024 CVE Published
- Apr 24, 2026 CVE Updated
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Distribution Patch
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
- Apr 25, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:4126 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://docs.redhat.com/en/documentation/red_hat_service_interconnect/1.4 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2268019 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2268273 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4126.json advisory
- https://access.redhat.com/security/cve/CVE-2024-2961 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2273404 issue
- https://www.cve.org/CVERecord?id=CVE-2024-2961 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-2961 advisory
- https://www.openwall.com/lists/oss-security/2024/04/17/9 advisory
- https://access.redhat.com/security/cve/CVE-2024-33599 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2277202 issue
- https://www.cve.org/CVERecord?id=CVE-2024-33599 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-33599 advisory
- https://access.redhat.com/security/cve/CVE-2024-33600 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2277204 issue
- https://www.cve.org/CVERecord?id=CVE-2024-33600 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-33600 advisory
- https://access.redhat.com/security/cve/CVE-2024-33601 advisory
…and 7 more