cbcvebase.
CVE-2021-22945
published 2021-09-23

CVE-2021-22945: When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and…

critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

Affected

23 ranges
VendorProductVersion rangeFixed in
applemacos>= 12.0.0 < 12.312.3
applemacos_monterey
debiancurl< curl 7.79.1-1 (bookworm)curl 7.79.1-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
haxxcurl>= 0 < 7.74.0-1.3+deb11u27.74.0-1.3+deb11u2
haxxcurl>= 0 < 7.79.1-17.79.1-1
haxxcurl>= 0 < 7.79.1-17.79.1-1
haxxcurl>= 0 < 7.79.1-17.79.1-1
haxxcurl>= 0 < 7.58.0-2ubuntu3.167.58.0-2ubuntu3.16
haxxcurl>= 0 < 7.58.0-2ubuntu3.157.58.0-2ubuntu3.15
haxxcurl>= 0 < 7.68.0-1ubuntu2.77.68.0-1ubuntu2.7
haxxlibcurl7.73.0 – 7.78.0
httpsgithub.com_curl_curl
msrccbl2_curl_7.82.0-1_on_cbl_mariner_2.0
msrccm1_curl_7.76.0-6_on_cbl_mariner_1.0
oraclemysql_server5.7.0 – 5.7.35
oraclemysql_server8.0.0 – 8.0.26
siemenssinec_ins< 1.0.1.11.0.1.1
splunkuniversal_forwarder
splunkuniversal_forwarder>= 8.2.0 < 8.2.128.2.12
splunkuniversal_forwarder>= 9.0.0 < 9.0.69.0.6

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL