Vulnerability CVE-2021-37959: Information

Description

Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.

Severity: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Oct. 9, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-416

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
chromiumsisyphus94.0.4606.54-alt1124.0.6367.78-alt1ALT-PU-2021-2909-1285978Fixed
chromiump1094.0.4606.71-alt1119.0.6045.159-alt0.p10.1ALT-PU-2021-2988-1286231Fixed
chromiump994.0.4606.81-alt0.p9.197.0.4692.99-alt0.p9.1ALT-PU-2021-3044-1285873Fixed
chromiumc10f194.0.4606.71-alt1110.0.5481.177-alt1.p10.1ALT-PU-2021-2988-1286231Fixed
chromium-gostsisyphus94.0.4606.71-alt1121.0.6167.160-alt1ALT-PU-2021-2987-1286559Fixed
chromium-gostp1094.0.4606.71-alt2110.0.5481.177-alt1.p10.1ALT-PU-2021-3050-1286785Fixed
chromium-gostp996.0.4664.45-alt2.p9.196.0.4664.45-alt2.p9.1ALT-PU-2021-3603-1291751Fixed
chromium-gostc10f194.0.4606.71-alt2110.0.5481.177-alt1.p10.1ALT-PU-2021-3050-1286785Fixed
chromium-gostc9f296.0.4664.45-alt2.c9.196.0.4664.45-alt2.c9.1ALT-PU-2021-3436-1284092Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
      End excliding
      94.0.4606.54

      Configuration 2

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*