]> git.ipfire.org Git - thirdparty/glibc.git/commit
CVE-2024-33600: nscd: Do not send missing not-found response in addgetnetgrentX ...
authorFlorian Weimer <fweimer@redhat.com>
Thu, 25 Apr 2024 13:01:07 +0000 (15:01 +0200)
committerFlorian Weimer <fweimer@redhat.com>
Thu, 25 Apr 2024 14:07:52 +0000 (16:07 +0200)
commitf20a8d696b13c6261b52a6434899121f8b19d5a7
treeef86afe358dd0b1d2e5cb1dc0dd03c991ac8e985
parent5c75001a96abcd50cbdb74df24c3f013188d076e
CVE-2024-33600: nscd: Do not send missing not-found response in addgetnetgrentX (bug 31678)

If we failed to add a not-found response to the cache, the dataset
point can be null, resulting in a null pointer dereference.

Reviewed-by: Siddhesh Poyarekar <siddhesh@sourceware.org>
(cherry picked from commit 7835b00dbce53c3c87bbbb1754a95fb5e58187aa)
nscd/netgroupcache.c