Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-33640


After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).


Published

2022-12-19T16:15:10.840

Last Modified

2025-04-02T18:33:53.340

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.2 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-416
  • Type: Primary
    CWE-416

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System openatom openeuler 20.03 Yes
Operating System openatom openeuler 20.03 Yes
Operating System openatom openeuler 22.03 Yes
Operating System fedoraproject fedora 36 Yes
Operating System fedoraproject fedora 37 Yes

References