CVE-2021-38604
published 2021-08-12CVE-2021-38604: In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | — | — |
| fedoraproject | fedora | — | — |
| gnu | glibc | <= 2.34 | — |
| gnu | glibc | >= 0 < 2.34-0ubuntu3 | 2.34-0ubuntu3 |
| msrc | cbl2_glibc_2.35-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_glibc_2.28-20_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| oracle | enterprise_operations_monitor | — | — |
| oracle | enterprise_operations_monitor | — | — |
| oracle | enterprise_operations_monitor | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL