The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
https://sourceware.org/bugzilla/show_bug.cgi?id=27462 | issue tracking third party advisory patch |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/ | vendor advisory |
https://security.gentoo.org/glsa/202107-07 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html | third party advisory mailing list |