The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
2021-05-25T22:15:10.410
2024-11-21T06:09:07.140
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnu | glibc | 2.32 | Yes |
Application | gnu | glibc | 2.33 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Application | netapp | cloud_backup | - | Yes |
Application | netapp | e-series_santricity_os_controller | ≤ 11.70.1 | Yes |
Operating System | netapp | solidfire_baseboard_management_controller_firmware | - | Yes |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h300s | - | No |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | h300e_firmware | - | Yes |
Hardware | netapp | h300e | - | No |
Operating System | netapp | h500e_firmware | - | Yes |
Hardware | netapp | h500e | - | No |
Operating System | netapp | h700e_firmware | - | Yes |
Hardware | netapp | h700e | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Operating System | debian | debian_linux | 10.0 | Yes |