PT-2021-7325 · Unknown+8 · Gnu C Library+8

Siddhesh Poyarekar

·

Published

2021-02-24

·

Updated

2025-06-09

·

CVE-2021-27645

CVSS v3.1

2.5

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GNU C Library versions 2.29 through 2.33
Description The nameserver caching daemon (nscd) in the GNU C Library, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This issue is related to the netgroupcache.c component.
Recommendations For GNU C Library versions 2.29 through 2.33, consider disabling the netgroupcache.c component or restricting its use until a patch is available to prevent potential Denial of Service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4358
ALT-PU-2021-2862
ALT-PU-2021-2880
ALT-PU-2021-3034
BDU:2022-05689
CESA-2021_4358
CVE-2021-27645
DLA-3152-1
MGASA-2021-0138
MGASA-2021-0150
OPENSUSE-SU-2024:10792-1
RHSA-2021:4358
RHSA-2021_4358
RLSA-2021:4358
USN-5310-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Gnu C Library
Linuxmint
Red Hat
Rocky Linux
Ubuntu