CVE-2024-33600

medium
Published 2024-05-23 · Modified 2024-05-28
CVSS v3
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2
VIR risk
5.9

Description

Important: glibc security update

Predictions

Exploit likelihood
69%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-3339.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2273404

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-3344.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2277206

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2277205

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2277204

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2277202

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:3344

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:3339

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-33600.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-33600

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:3344

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:3339

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
debian debianbookwormfixed2.36-9+deb12u7
debian debianbullseyefixed2.31-13+deb11u10
debian debianforkyfixed2.37-19
debian debiansidfixed2.37-19
debian debiantrixiefixed2.37-19
suse slesaffected
rockylinux rocky9fixed
debian debian10.0affected

Application impact

VendorProductVersionsFixed
gnuglibc{"startIncluding":"2.15","endExcluding":"2.40"}2.40
netappactive_iq_unified_manager-

References

CWEs

CWE-476

Verify integrity in audit chain (admin only). AS-IS.