/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-56433

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-56433

Severity

3.6

Low

CVSS V3

Description

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

References

  • https://images.chainguard.dev/security/CGA-9hhf-fv89-f4vc

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing