Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE Linux Enterprise Micro: SUSE-SU-2024:1895-2 Important: glibc Issues

suse
Calendar Grey July 31, 2024
Dist Suse Esm H88
Important glibc patch released for SUSE to fix several security flaws. Update immediately to enhance protection on your machine.
* bsc#1221940 * bsc#1223423 * bsc#1223424 * bsc#1223425

Summary

## This update for glibc fixes the following issues: * CVE-2024-33599: Fixed a stack-based buffer overflow in netgroup cache in nscd (bsc#1223423) * CVE-2024-33600: Avoid null pointer crashes after notfound response in nscd (bsc#1223424) * CVE-2024-33600: Do not send missing not-found response in addgetnetgrentX in nscd (bsc#1223424) * CVE-2024-33601, CVE-2024-33602: Fixed use of two buffers in addgetnetgrentX ( bsc#1223425) * CVE-2024-33602: Use time_t for return type of addgetnetgrentX (bsc#1223425) * Avoid creating userspace live patching prologue for _start routine (bsc#1221940) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

* bsc#1221940

* bsc#1223423

* bsc#1223424

* bsc#1223425

Cross-

* CVE-2024-33599

* CVE-2024-33600

* CVE-2024-33601

* CVE-2024-33602

CVSS scores:

* CVE-2024-33599 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

* CVE-2024-33600 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-33601 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-33602 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products:

* SUSE Linux Enterprise Micro 5.5

An update that solves four vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2024-33599.html

* https://www.suse.com/security/cve/CVE-2024-33600.html

* https://www.suse.com/security/cve/CVE-2024-33601.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:1895-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here