PT-2024-36816 · Unknown+4 · Shadow-Utils+4

Jonnywhatshisface

·

Published

2024-12-26

·

Updated

2025-12-31

·

CVE-2024-56433

CVSS v3.1

3.6

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions shadow-utils versions 4.4 through 4.17.0
Description The issue arises from the default /etc/subuid behavior established by shadow-utils, which can conflict with the uids of users defined on locally administered networks. This conflict can potentially lead to account takeover, for example, by leveraging newuidmap for access to an NFS home directory or same-host resources in the case of remote logins by these local network users. It is also noted that system administrators should avoid assigning uids within local networks that fall within the range that can occur in /etc/subuid.
Recommendations For shadow-utils versions 4.4 through 4.17.0, consider adjusting the /etc/subuid configuration to avoid conflicts with locally administered network user ids. As a temporary workaround, restrict access to newuidmap to minimize the risk of account takeover. Avoid using uid ranges in /etc/subuid that overlap with those used by local network users.

Fix

Weakness Enumeration

Related Identifiers

ALSA-2025:20145
ALSA-2025:20559
AZL-54674
CVE-2024-56433
ECHO-1445-D49A-1C4B
INFSA-2025_20559
RHSA-2025:20145
RHSA-2025:20559
RHSA-2025_20559

Affected Products

Almalinux
Debian
Red Hat
Rocky Linux
Shadow-Utils