{
  "document": {
    "aggregate_severity": {
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2024/cve-2024-56433-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T18:41:55Z",
      "generator": {
        "date": "2026-07-28T18:41:54Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2024-56433-ELS_OS-RHEL7ELS",
      "initial_release_date": "2024-12-26T00:00:00Z",
      "revision_history": [
        {
          "date": "2024-12-26T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T15:55:53Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-28T18:41:55Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2024-56433"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "shadow-utils-2:4.6-5.el7.x86_64",
                "product": {
                  "name": "shadow-utils-2:4.6-5.el7.x86_64",
                  "product_id": "shadow-utils-2:4.6-5.el7.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/shadow-utils@4.6-5.el7?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
                "product": {
                  "name": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
                  "product_id": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/shadow-utils@4.6-5.el7.tuxcare.els1?arch=x86_64&epoch=2"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64"
        },
        "product_reference": "shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "shadow-utils-2:4.6-5.el7.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:shadow-utils-2:4.6-5.el7.x86_64"
        },
        "product_reference": "shadow-utils-2:4.6-5.el7.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-56433",
      "cwe": {
        "id": "CWE-1188",
        "name": "Initialization of a Resource with an Insecure Default"
      },
      "notes": [
        {
          "category": "description",
          "text": "shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
          "Red-Hat-7:shadow-utils-2:4.6-5.el7.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-56433"
        }
      ],
      "release_date": "2024-12-26T00:00:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T17:03:33.352863Z",
          "details": "This issue is local-only and requires a logged-in user to create a user namespace with newuidmap and target a resource that authorizes strictly by numeric UID (such as certain NFS configurations) where a network user’s UID actually overlaps the host’s default /etc/subuid range. It does not yield host privilege escalation; impact is limited to acting as the overlapping UID on that external resource, with unchanged scope and no availability effect. In centrally managed server/VM environments, subordinate-ID ranges are explicitly defined in /etc/subuid and can be coordinated with directory/NFS UID spaces, so without a real UID collision and a UID-based trust boundary, there is no practical exploit path.",
          "product_ids": [
            "Red-Hat-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:shadow-utils-2:4.6-5.el7.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 3.6,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:shadow-utils-2:4.6-5.el7.tuxcare.els1.x86_64",
            "Red-Hat-7:shadow-utils-2:4.6-5.el7.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    }
  ]
}