{
  "document": {
    "aggregate_severity": {
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos7els/vex/2024/cve-2024-56433-els_os-centos7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T14:41:46Z",
      "generator": {
        "date": "2026-07-28T14:41:46Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2024-56433-ELS_OS-CENTOS7ELS",
      "initial_release_date": "2024-12-26T00:00:00Z",
      "revision_history": [
        {
          "date": "2024-12-26T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T01:34:07Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-28T14:41:46Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2024-56433"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 7",
                "product": {
                  "name": "Community Enterprise Operating System 7",
                  "product_id": "CentOS-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "shadow-utils-2:4.6-5.el7.x86_64",
                "product": {
                  "name": "shadow-utils-2:4.6-5.el7.x86_64",
                  "product_id": "shadow-utils-2:4.6-5.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/shadow-utils@4.6-5.el7?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
                  "product_id": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/shadow-utils@4.6-5.el7.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "shadow-utils-2:4.6-5.el7.x86_64 as a component of Community Enterprise Operating System 7",
          "product_id": "CentOS-7:shadow-utils-2:4.6-5.el7.x86_64"
        },
        "product_reference": "shadow-utils-2:4.6-5.el7.x86_64",
        "relates_to_product_reference": "CentOS-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-56433",
      "cwe": {
        "id": "CWE-1188",
        "name": "Initialization of a Resource with an Insecure Default"
      },
      "notes": [
        {
          "category": "description",
          "text": "shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
          "CentOS-7:shadow-utils-2:4.6-5.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-56433"
        }
      ],
      "release_date": "2024-12-26T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T12:32:38.740342Z",
          "details": "CVE-2024-56433 is a local, high‑complexity, configuration‑dependent issue where the default subordinate‑UID range (e.g., 100000–165535) can only be abused if a local user already has a /etc/subuid entry and can use the setuid newuidmap helper to target services that trust raw numeric UIDs (such as AUTH_SYS NFS) in that same range. It does not provide root privilege escalation or affect availability; any data exposure arises only under those specific authorization models and UID assignments. Given these narrow preconditions and the limited impact, this CVE can be safely deprioritized relative to remotely exploitable or privilege‑escalation vulnerabilities.",
          "product_ids": [
            "CentOS-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
            "CentOS-7:shadow-utils-2:4.6-5.el7.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 3.6,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CentOS-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
            "CentOS-7:shadow-utils-2:4.6-5.el7.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    }
  ]
}