Red Hat released Important glibc security updates for Red Hat Enterprise Linux 7, 8, and 9—including extended, advanced-update, and extended-lifecycle support channels—to remediate CVE-2024-2961. The flaw affects the ISO-2022-CN-EXT iconv conversion module: incomplete internal-buffer checks for SS2 and SS3 charset-switch escape sequences during UCS-4 conversion can write one to three bytes beyond the intended buffer. Red Hat assigned the issue a CVSS v3.1 score of 8.8; successful exploitation may cause memory corruption, denial of service, privilege escalation, or remote code execution depending on the calling application and conditions.
The updates also resolve four glibc/nscd netgroup-cache vulnerabilities, including a stack-based buffer overflow, null-pointer dereferences, allocation-failure daemon termination, and unsafe handling of NSS callback strings. Administrators should deploy the updated glibc packages across affected x86_64, ARM64/aarch64, IBM Z/s390x, and IBM Power architectures, then restart all glibc-linked services or reboot hosts. Where patching cannot be performed immediately, Red Hat recommends disabling the vulnerable ISO-2022-CN-EXT gconv module and rebuilding the iconv cache; fixes were also issued for OpenShift Container Platform 4.12 through 4.16.

See affected versions and whether adversaries are exploiting it.
55 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2024:3993 updating STF-1.5-RHEL-8 container images for Red Hat OpenStack 1 on RHEL 8 x86_64. The images backport fixes including CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent images.
Red Hat issued RHBA-2024:3981 for updated RHEL 7-based Middleware Containers, including AMQ 7 Interconnect and AMQ 7 Interconnect Operator images. The update backports RHSA-2024:3588 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade images and rebuild dependent containers.
Red Hat issued RHBA-2024:3944 to update the jboss-datagrid-7/datagrid73-openshift container image for RHEL 7-based Middleware Containers. The image backports RHSA-2024:3588 fixes for CVE-2024-2961 and glibc netgroup-cache flaws; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3966 to update the x86_64 gatekeeper/gatekeeper-operator-bundle container image for Gatekeeper 3.14 on RHEL 9. The image backports fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3873 to update Gatekeeper 3.14 container images for RHEL 9 across aarch64, ppc64le, s390x, and x86_64. The update remediates CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the images and rebuild dependent containers.
Red Hat issued RHBA-2024:3870 to update RHEL 7-based Middleware Containers images for OpenShift Container Platform 4.8 and 4.9 across x86_64, ppc64le, and s390x. The update backports RHSA-2024:3588 fixes for CVE-2024-2961 and four glibc netgroup-cache vulnerabilities; users were advised to pull updated images and rebuild dependent containers.
Red Hat issued RHBA-2024:3853 for updated Red Hat OpenStack Platform 17.1 container images on RHEL 9 x86_64. The update backports RHSA-2024:3411 fixes for CVE-2024-2961 and four glibc netgroup-cache vulnerabilities; customers were advised to upgrade and rebuild dependent images.
Red Hat issued RHBA-2024:3735 to update RHEL 7-based Middleware Containers images, incorporating RHSA-2024:3588 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602. Users were advised to pull the updated images from the Red Hat Container Registry and rebuild dependent container images.
Red Hat issued RHBA-2024:3628 updating Red Hat Software Collections container images for RHEL 7, including devtoolset-12 perftools and toolchain images. The update backports fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the images and rebuild dependent containers.
Red Hat issued RHBA-2024:3616 to update the devtools/go-toolset-rhel7 container image for Red Hat Developer Tools. The update backports RHSA-2024:3588 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent container images.
Red Hat issued RHBA-2024:3615 to update the jboss-amq-6/amq63-openshift container image for RHEL 7-based Middleware Containers on OpenShift Container Platform 3.11. The update backports RHSA-2024:3588 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent images.
Red Hat issued Important-rated RHSA-2024:3588 for RHEL 7, providing glibc 2.17-326.el7_9.3 to remediate CVE-2024-2961 and four glibc/nscd netgroup-cache vulnerabilities.
Red Hat issued RHBA-2024:3548 to update Cryostat 2 container images for RHEL 8 x86_64. The images backport fixes for 15 CVEs, including glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent images.
Red Hat issued RHBA-2024:3554 to update the RHEL 8 Universal Base Image (ubi8) container image. The image backports fixes for CVE-2023-6597, CVE-2024-0450, and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to update base images and rebuild dependent containers.
Red Hat issued RHBA-2024:3532 to update the rhel9/skopeo and ubi9/skopeo container images for RHEL 9 across aarch64, ppc64le, s390x, and x86_64. The images backport RHSA-2024:3339 fixes for CVE-2024-2961 and four glibc netgroup-cache vulnerabilities; users were advised to upgrade the images and rebuild dependent containers.
Red Hat issued RHBA-2024:3511 to update the rhel9/support-tools container image for RHEL 9 across aarch64, ppc64le, s390x, and x86_64. The image backports RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3506 to update the rhel9/buildah container image for RHEL 9 across supported architectures. The image backports RHSA-2024:3339 fixes for CVE-2024-2961 and four glibc netgroup-cache vulnerabilities; users were advised to upgrade the image and rebuild downstream container images.
Red Hat issued RHBA-2024:3508 to update the rhel9/net-snmp container image for RHEL 9 across x86_64, aarch64, ppc64le, and s390x. The image incorporates RHSA-2024:3339 fixes for CVE-2024-2961 and four glibc netgroup-cache vulnerabilities; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3510 to update the rhel9/podman and ubi9/podman container images for RHEL 9 across supported architectures. The images backport RHSA-2024:3339 fixes for CVE-2024-2961 and four glibc netgroup-cache flaws; users were advised to upgrade the images and rebuild downstream containers.
Red Hat issued RHBA-2024:3509 for an updated rhel9/rsyslog container image for RHEL 9. The image backports RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache vulnerabilities; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3451 to update the rhel8/net-snmp container image across supported RHEL 8 architectures. The image incorporates RHSA-2024:3344 fixes for CVE-2023-6597, CVE-2024-0450, and four glibc netgroup-cache flaws; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3468 to update RHDH-1.1-RHEL-9 container images for Red Hat Developer Hub 1 on x86_64. The update backports RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent images.
Red Hat issued RHBA-2024:3477 for updated Red Hat OpenStack Platform 16.2 container images on x86_64 and IBM Power ppc64le. The images backport fixes for CVE-2024-2961 and glibc netgroup-cache vulnerabilities; users were advised to update image references and rebuild dependent container images.
Red Hat issued RHBA-2024:3463 to update the ubi9-minimal container image for RHEL 9 across x86_64, aarch64, ppc64le, and s390x. The image backports fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to pull the updated image and rebuild dependent containers.
Red Hat issued RHBA-2024:3456 to update the Universal Base Image 9 (ubi9) container image for RHEL 9 across supported architectures. The update backports fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the base image and rebuild dependent container images.
Red Hat issued RHBA-2024:3459 to update the ubi9/ubi-micro container image for RHEL 9 across supported architectures. The image backports fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent container images.
Red Hat issued RHBA-2024:3458 to update the ubi9/ubi9-init container image for RHEL 9 across supported architectures. The image incorporates fixes for CVE-2024-2961 and glibc netgroup-cache vulnerabilities CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the base image and rebuild dependent containers.
Red Hat issued RHBA-2024:3457 to update the rhel-els container image for RHEL 9 across supported architectures. The image backports RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache vulnerabilities CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent container images.
Red Hat issued Important-rated RHSA-2024:3464 for RHEL Server 8.2 Advanced Update Support on x86_64, supplying glibc 2.28-101.el8_2.2 to fix CVE-2024-2961 and four netgroup-cache flaws.
Red Hat issued RHBA-2024:3371 to update RHEL 9 container images, including Flatpak runtime and SDK images, incorporating RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache vulnerabilities. The advisory also listed CVE-2024-26642, CVE-2024-26643, CVE-2024-26673, and CVE-2024-26804, and directed users to upgrade images and rebuild dependent containers.
Red Hat issued RHBA-2024:3366 to update the rhel9/pcp container image across supported RHEL 9 architectures. The image incorporates RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache vulnerabilities CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3367 to update the rhel9/tang container image for RHEL 9 across supported architectures. The image incorporates RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent container images.
Red Hat issued RHBA-2024:3365 to update the rhel9/squid container image for RHEL 9 across supported architectures. The image incorporates RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3430 for updated Red Hat OpenStack Platform 17.1 container images on RHEL 8 x86_64, addressing CVE-2024-2961 and netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602. Users were advised to upgrade the images and rebuild dependent container images.
Red Hat issued RHBA-2024:3363 to update the rhel9/memcached container image for RHEL 9 across aarch64, ppc64le, s390x, and x86_64. The image backports RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade and rebuild dependent container images.
Red Hat issued RHBA-2024:3362 to update the rhel9/keylime-registrar and rhel9/keylime-verifier container images across supported architectures. The images incorporate RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache vulnerabilities; users were advised to update image references and rebuild dependent containers.
Red Hat issued RHBA-2024:3398 to update the rhdh/rhdh-hub-rhel9 image for Red Hat Developer Hub 1.0 on RHEL 9. The image backports fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3383, updating RHEL 9 and UBI 9 application container images across supported architectures and update-service channels. The images backport fixes for CVE-2024-2961 and netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade base images and rebuild dependent containers.
Red Hat issued RHBA-2024:3382 to update the rhel9/gcc-toolset-13-toolchain container image for RHEL 9, addressing CVE-2024-2961 and multiple glibc netgroup-cache vulnerabilities. Users were advised to upgrade the image and rebuild dependent container images.
Red Hat issued RHBA-2024:3380 to update the RHEL 9 toolbox-container image, addressing CVE-2024-2961 and four glibc netgroup-cache flaws. Users were advised to upgrade to the new image digests and rebuild dependent container images.
Red Hat issued RHBA-2024:3361 to update the rhel9/cups container image for RHEL 9 across aarch64, ppc64le, s390x, and x86_64. The image incorporates RHSA-2024:3339 fixes for CVE-2024-2961 and four glibc netgroup-cache vulnerabilities; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued RHBA-2024:3360 to update the rhel9/grafana container image for RHEL 9 across supported architectures. The image incorporates RHSA-2024:3339 fixes for CVE-2024-2961 and glibc netgroup-cache flaws CVE-2024-33599 through CVE-2024-33602; users were advised to upgrade the image and rebuild dependent containers.
Red Hat issued Important-rated RHSA-2024:3423 for RHEL 9.0 Extended Update Support and selected SAP update-service offerings, updating glibc to fix CVE-2024-2961 and four netgroup-cache vulnerabilities.
Red Hat published RHSA-2024:3312 for RHEL 8.8 Extended Update Support, remediating CVE-2024-2961 and four additional glibc netgroup-cache vulnerabilities.
Red Hat issued Important-rated RHSA-2024:3339 for RHEL 9, fixing the CVE-2024-2961 ISO-2022-CN-EXT iconv out-of-bounds write and four netgroup-cache flaws.
Red Hat published Important-security advisory RHSA-2024:3269, updating glibc for RHEL 8 and associated CodeReady Linux Builder repositories to fix CVE-2024-2961.
Red Hat issued RHBA-2024:2851 to update the rhel-els container image for RHEL 8.6 Extended Update Support. The image incorporates fixes for CVE-2024-2961 and four glibc netgroup-cache vulnerabilities; users were advised to upgrade the image and rebuild dependent container images.
Red Hat issued RHSA-2024:2799 for RHEL 8.6 Extended Update Support, remediating CVE-2024-2961 in glibc iconv along with four netgroup-cache vulnerabilities.
Red Hat issued Important-rated advisory RHSA-2024:2722 for RHEL 8, fixing CVE-2024-2961, an out-of-bounds write in glibc iconv that may permit remote code execution.
Robb Gatica reported CVE-2024-33601 to Red Hat as Bug 2277205. The low-severity glibc netgroup-cache flaw can terminate a daemon when xmalloc or xrealloc fails during memory allocation.
Robb Gatica reported CVE-2024-33602 to Red Hat as Bug 2277206. The low-severity glibc flaw stems from addgetnetgrentX buffer-resizing logic assuming NSS callback string pointers are within the supplied buffer.
Red Hat documented CVE-2024-0450, in which CPython's zipfile module can process quoted-overlap ZIP bombs with overlapping entries that produce extreme compression ratios and resource consumption. Fixed CPython releases reject ZIP archives containing overlapping entries; Red Hat issued remediation advisories for RHEL 8, RHEL 9, RHEL 8.8 EUS, RHEL 8.6 update-service variants, and RHEL 9 Service Interconnect.
Red Hat documented CVE-2024-33599, a stack-based buffer overflow in nscd's netgroup-cache handling that can occur when mempool_alloc fails and the code copies key material beyond a fixed-size stack fallback structure. Red Hat linked fixes across RHEL 7, 8, and 9 streams and advised disabling netgroup caching as a workaround when affected.
Red Hat documented CVE-2024-33600, in which glibc nscd can mishandle a NULL result from addgetnetgrentX after a failed netgroup-cache insertion and attempt to prepare a nonexistent response. Red Hat linked the flaw to errata across RHEL 7, 8, and 9, including extended-support and specialized update-service channels.
Red Hat later addressed CVE-2024-2961 in OpenShift Container Platform 4.12 through 4.16 through advisories RHSA-2024:7590, RHSA-2024:7939, RHSA-2024:8235, RHSA-2024:7594, and RHSA-2024:7599.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.