Vulnerability CVE-2021-33574: Information
Description
The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
glibc | sisyphus | 2.32-alt3 | 2.38.0.66.ge1135387de-alt1 | ALT-PU-2021-2137-1 | 276954 | Fixed |
glibc | sisyphus_e2k | 2.35.0.234.3f63f9dfe1-alt1.E2K.27.020.2 | 2.35.0.234.3f63f9dfe1-alt1.E2K.27.020.4 | ALT-PU-2024-1492-1 | - | Fixed |
glibc | sisyphus_riscv64 | 2.34.0.39.024a7-alt1.rv64 | 2.38.0.44.d37c2b20a4-alt1 | ALT-PU-2021-4728-1 | - | Fixed |
glibc | p10 | 2.32-alt3 | 2.32-alt5.p10.2 | ALT-PU-2021-2137-1 | 276954 | Fixed |
glibc | c10f1 | 2.32-alt3 | 2.32-alt5.p10.2 | ALT-PU-2021-2137-1 | 276954 | Fixed |
References to Advisories, Solutions, and Tools
Hyperlink | Resource |
---|---|
https://sourceware.org/bugzilla/show_bug.cgi?id=27896 |
|
https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1 |
|
https://security.netapp.com/advisory/ntap-20210629-0005/ |
|
GLSA-202107-07 |
|
[debian-lts-announce] 20221017 [SECURITY] [DLA 3152-1] glibc security update |
|
FEDORA-2021-7ddb8b0537 | |
FEDORA-2021-f29b4643c7 |