cbcvebase.
CVE-2021-33574
published 2021-05-25

CVE-2021-33574: The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianglibc< glibc 2.32-1 (bookworm)glibc 2.32-1 (bookworm)
debianglibc
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
gnuglibc<= 2.34
gnuglibc
gnuglibc
gnuglibc>= 0 < 2.31-13+deb11u32.31-13+deb11u3
gnuglibc>= 0 < 2.32-12.32-1
gnuglibc>= 0 < 2.32-12.32-1
gnuglibc>= 0 < 2.32-12.32-1
gnuglibc>= 0 < 2.34-0ubuntu32.34-0ubuntu3
msrccbl2_glibc_2.35-1_on_cbl_mariner_2.0
msrccm1_glibc_2.28-20_on_cbl_mariner_1.0
netappe-series_santricity_os_controller11.0 – 11.70.1
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_cloud_native_core_unified_data_repository
oracleenterprise_operations_monitor
oracleenterprise_operations_monitor

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL