cbcvebase.
CVE-2021-38604
published 2021-08-12

CVE-2021-38604: In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianglibc
fedoraprojectfedora
gnuglibc<= 2.34
gnuglibc>= 0 < 2.34-0ubuntu32.34-0ubuntu3
msrccbl2_glibc_2.35-1_on_cbl_mariner_2.0
msrccm1_glibc_2.28-20_on_cbl_mariner_1.0
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_function_cloud_native_environment
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_network_repository_function
oraclecommunications_cloud_native_core_security_edge_protection_proxy
oraclecommunications_cloud_native_core_unified_data_repository
oracleenterprise_operations_monitor
oracleenterprise_operations_monitor
oracleenterprise_operations_monitor

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.8CRITICAL