CVE-2021-33574
published 2021-05-25CVE-2021-33574: The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object…
PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.90%
85.4th percentile
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | glibc | < glibc 2.32-1 (bookworm) | glibc 2.32-1 (bookworm) |
| debian | glibc | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | glibc | <= 2.34 | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | >= 0 < 2.31-13+deb11u3 | 2.31-13+deb11u3 |
| gnu | glibc | >= 0 < 2.32-1 | 2.32-1 |
| gnu | glibc | >= 0 < 2.32-1 | 2.32-1 |
| gnu | glibc | >= 0 < 2.32-1 | 2.32-1 |
| gnu | glibc | >= 0 < 2.34-0ubuntu3 | 2.34-0ubuntu3 |
| msrc | cbl2_glibc_2.35-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_glibc_2.28-20_on_cbl_mariner_1.0 | — | — |
| netapp | e-series_santricity_os_controller | 11.0 – 11.70.1 | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| oracle | enterprise_operations_monitor | — | — |
| oracle | enterprise_operations_monitor | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS
cisa_ics·2023-06-15·CVSS 5.9
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP BIOS
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP BIOS
Release DateJune 15, 2023
Alert CodeICSA-23-166-10
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Improper Input Validation, Out-of-bounds Read, Use After Free, Out-of-bounds Write, Infinite Loop, Reachable Assertion, Off-by-one Error, Incorrect Default Permissions, Double Fr
Microsoft
In librt in the GNU C Library (aka glibc) through 2.34 sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data leading to a NULL pointer dereference. NOTE: this vulnerability was in
vendor_msrc·2021-08-10·CVSS 7.5
CVE-2021-38604 [CRITICAL] CWE-476 In librt in the GNU C Library (aka glibc) through 2.34 sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data leading to a NULL pointer dereference. NOTE: this vulnerability was in
In librt in the GNU C Library (aka glibc) through 2.34 sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to a
Red Hat
glibc: NULL pointer dereference in helper_thread() in mq_notify.c while handling NOTIFY_REMOVED messages
vendor_redhat·2021-08-09·CVSS 9.8
CVE-2021-38604 [CRITICAL] CWE-476 glibc: NULL pointer dereference in helper_thread() in mq_notify.c while handling NOTIFY_REMOVED messages
glibc: NULL pointer dereference in helper_thread() in mq_notify.c while handling NOTIFY_REMOVED messages
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
A flaw was found in the GNU C library (glibc), where the sysdeps/unix/sysv/linux/mq_notify.c function mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. The highest threat from this vulnerability is to system availability.
Statement: This vulnerability was introduced as a side effect of the fix for CVE-2021-33574. No version of Red Hat Enterprise Linux included the version of the fix for CVE-2021-33574 int
Red Hat
glibc: mq_notify does not handle separately allocated thread attributes
vendor_redhat·2021-05-21·CVSS 9.8
CVE-2021-33574 [CRITICAL] CWE-416 glibc: mq_notify does not handle separately allocated thread attributes
glibc: mq_notify does not handle separately allocated thread attributes
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
The mq_notify function in the GNU C Library (aka glibc) has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Statement: In order to mount a minimal attack using this flaw, an attacker needs many pre-
Microsoft
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter)
vendor_msrc·2021-05-11·CVSS 9.8
CVE-2021-33574 [CRITICAL] CWE-416 The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter)
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller leading to a denial of service (application crash) or possibly unspecified other impact.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/V
Debian
CVE-2021-38604: glibc - In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/...
vendor_debian·2021·CVSS 9.8
CVE-2021-38604 [CRITICAL] CVE-2021-38604: glibc - In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/...
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2021-33574: glibc - The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 h...
vendor_debian·2021·CVSS 9.8
CVE-2021-33574 [CRITICAL] CVE-2021-33574: glibc - The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 h...
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Scope: local
bookworm: resolved (fixed in 2.32-1)
bullseye: resolved (fixed in 2.31-13+deb11u3)
forky: resolved (fixed in 2.32-1)
sid: resolved (fixed in 2.32-1)
trixie: resolved (fixed in 2.32-1)
GHSA
GHSA-p3v7-wjmc-7fh8: In librt in the GNU C Library (aka glibc) through 2
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2021-38604 [CRITICAL] CWE-476 GHSA-p3v7-wjmc-7fh8: In librt in the GNU C Library (aka glibc) through 2
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
GHSA
GHSA-rx5m-j84j-22pg: The mq_notify function in the GNU C Library (aka glibc) through 2
ghsa_unreviewed·2022-05-24
CVE-2021-33574 [CRITICAL] CWE-416 GHSA-rx5m-j84j-22pg: The mq_notify function in the GNU C Library (aka glibc) through 2
The mq_notify function in the GNU C Library (aka glibc) through 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
OSV
CVE-2021-38604: In librt in the GNU C Library (aka glibc) through 2
osv·2021-08-12·CVSS 9.8
CVE-2021-38604 [CRITICAL] CVE-2021-38604: In librt in the GNU C Library (aka glibc) through 2
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
OSV
CVE-2021-33574: The mq_notify function in the GNU C Library (aka glibc) versions 2
osv·2021-05-25·CVSS 9.8
CVE-2021-33574 [CRITICAL] CVE-2021-33574: The mq_notify function in the GNU C Library (aka glibc) versions 2
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/https://security.gentoo.org/glsa/202107-07https://security.netapp.com/advisory/ntap-20210629-0005/https://sourceware.org/bugzilla/show_bug.cgi?id=27896https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1https://lists.debian.org/debian-lts-announce/2022/10/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/https://security.gentoo.org/glsa/202107-07https://security.netapp.com/advisory/ntap-20210629-0005/https://sourceware.org/bugzilla/show_bug.cgi?id=27896https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1
2021-05-25
Published