Permissions, Privileges, and Access Controls in shadow - CVE-2024-56433
Published: July 17, 2025
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to shadow-utils establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users).
Affected software
BIG-IP Next CNF
BIG-IP Next SPK
BIG-IP Next for Kubernetes
Fedora
DataStax Hyper-Converged Database
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
AppDynamics NodeJS Agent
Cryostat
shadow-utils
How to mitigate CVE-2024-56433
DataStax Hyper-Converged Database - update to 1.2.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3
AppDynamics NodeJS Agent - update to 25.12.1
Cryostat - update to 4.1.0
shadow-utils - update to 4.17.4-2.fc42
External References
Related Security Bulletins
- Privilege escalation in shadow-utils
- Privilege escalation in shadow-utils component used by BIG-IP Next SPK/CNF
- Privilege escalation in shadow-utils component used by BIG-IP Next for Kubernetes
- Fedora 42 update for shadow-utils
- Multiple vulnerabilities in Red Hat build of Cryostat
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Splunk AppDynamics NodeJS Agent update for third-party components
- Multiple vulnerabilities in IBM DataStax Hyper-Converged Database