Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-56433

15
FAUCET Score

CVE-2024-56433 describes a vulnerability in shadow-utils versions 4.4 through 4.17.0 where the default /etc/subuid range can overlap with UIDs of locally administered network users, potentially leading to account takeover. This vulnerability has a low severity CVSS score of 3.6, indicating a local attack vector with high attack complexity and limited impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.4, <= 4.17.0CPE match
cpe:2.3:a:shadow-maint:shadow-utils:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.6LOW

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 90th percentile among its peer group of 223 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

microsoftpatch availablevia msrc
Product: azl3 shadow-utils shadow-utils_4.18.0 on Azure Linux 3.0Fixed in: shadow-utils_4.18.0
microsoftpatch availablevia msrc
Product: 17498-17084Fixed in: shadow-utils_4.18.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: shadow-utils-2:4.9-15.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:bddcf7ab6d576572b6d60822c313ffebcd9869e4fde93e32ac327821f93cf32b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/model-opt-cuda-rhel9:sha256:14e32e88f1b89f59ed34a6d712746b82a6a54c6ed4727784f18aeff853abbdc7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AI Inference Server 3.2Fixed in: rhaiis/vllm-cuda-rhel9:sha256:dcb9d1cd005c40b6db6f893e56419e383b9dcc0d38315605cb1457e2af5354f7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/rhceph-8-rhel9:sha256:69c4edadc3bfd45dd982764b7f9d9a0f3a6d74d26a0443796aaa4a65455c62d1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:b4683720677a1e45efbfd291d8b130b530642221e8a55a49e931e1b8b2c81ac3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-ui-rhel9:sha256:310df392f638ef6eca1a26db024ae2cb617db5932f886d2acddc92fb7289e740
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: rhceph/rhceph-7-rhel9:sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: shadow-utils-2:4.15.0-8.el10
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: shadow-utils
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: shadow-utils
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: shadow-utils

Vendor Advisories (2)

redhatCVE-2024-56433Low

shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

Dec 26, 2024
microsoft2024-Dec/CVE-2024-56433Low

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Dec 10, 2024

References

github.com / shadow-maint/shadow/blob/e2512d5741d4a44bdd81a8c2d0029b6222728cf0/etc/login.defs
github.com / shadow-maint/shadow/issues/1157
github.com / shadow-maint/shadow/releases/tag/4.4