CVE-2024-33602
Gnu Glibc 2.15 – 2.40
Raw vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2024-33602 is a high-severity Return of Pointer Value Outside of Expected Range (CWE-466) vulnerability in Gnu Glibc. Its CVSS base score is 7.4 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked at the 33th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and SA-15 (Development Process, Standards, and Tools) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-31339
Vulnerability Data
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15…
more
when the cache was added to nscd. This vulnerability is only present in the nscd binary.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V1.4.1
Mitigating Controls (NIST 800-53 r5) AI
Developer testing and evaluation can discover functions that return pointers outside expected buffer bounds.
Requiring documented development standards and tools can enforce safe pointer arithmetic and bounds checking to avoid out-of-range returns.
Security engineering principles applied during design can include explicit pointer-range validation and safe memory handling.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices enforce bounds checking, static analysis, and pointer validation that directly prevent out-of-range pointer returns.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development can detect out-of-range pointer returns through static analysis and fuzzing.
Secure SDLC practices can include pointer-range validation and bounds checking to prevent out-of-range returns.
Application security requirements can mandate pointer safety and range validation to avoid returning invalid addresses.
Secure architecture principles can enforce memory-safety patterns that reduce the likelihood of out-of-range pointer returns.
Secure coding standards directly address pointer validation and bounds checking, mitigating this specific weakness.