CVE-2024-33600: nscd: Do not send missing not-found response in addgetnetgrentX ...
authorFlorian Weimer <fweimer@redhat.com>
Thu, 25 Apr 2024 13:01:07 +0000 (15:01 +0200)
committerAdrian Bunk <bunk@debian.org>
Sat, 29 Jun 2024 10:27:34 +0000 (13:27 +0300)
commitff7799c8ef8654e81e7add5bc5203e2c6a61e3a8
treed84766d96758b7ffb53c563cfd3073e1f35d4f7a
parent7ae50e61a902d0e4a9ddcdb025712d2852e581d1
CVE-2024-33600: nscd: Do not send missing not-found response in addgetnetgrentX (bug 31678)

If we failed to add a not-found response to the cache, the dataset
point can be null, resulting in a null pointer dereference.

Reviewed-by: Siddhesh Poyarekar <siddhesh@sourceware.org>
Gbp-Pq: Topic all
Gbp-Pq: Name git-0002-CVE-2024-33600-nscd-Do-not-send-missing-not-found-re.patch
nscd/netgroupcache.c