CVE-2021-33574
Summary
| CVE | CVE-2021-33574 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-25 22:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: glibc-2.33-16.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: glibc-2.32-8.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 27896 – mq_notify does not handle separately allocated thread attributes |
MISC |
sourceware.org |
|
| glibc: Multiple vulnerabilities (GLSA 202107-07) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 33 Update: glibc-2.32-8.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| 27896 – mq_notify does not handle separately allocated thread attributes |
MISC |
sourceware.org |
|
| [SECURITY] [DLA 3152-1] glibc security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 34 Update: glibc-2.33-16.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE-2021-33574 GNU C Library (glibc) Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159493 Oracle Enterprise Linux Security Update for glibc (ELSA-2021-4358)
- 159561 Oracle Enterprise Linux Security Update for glibc (ELSA-2021-9560)
- 180332 Debian Security Update for glibc (CVE-2021-33574)
- 181138 Debian Security Update for glibc (DLA 3152-1)
- 239791 Red Hat Update for glibc security (RHSA-2021:4358)
- 281629 Fedora Security Update for glibc (FEDORA-2021-7ddb8b0537)
- 281689 Fedora Security Update for glibc (FEDORA-2021-f29b4643c7)
- 353127 Amazon Linux Security Advisory for glibc : ALAS2-2022-1736
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 670537 EulerOS Security Update for glibc (EulerOS-SA-2021-2295)
- 670572 EulerOS Security Update for glibc (EulerOS-SA-2021-2330)
- 670616 EulerOS Security Update for glibc (EulerOS-SA-2021-2374)
- 670768 EulerOS Security Update for glibc (EulerOS-SA-2021-2526)
- 670792 EulerOS Security Update for glibc (EulerOS-SA-2021-2550)
- 670928 EulerOS Security Update for glibc (EulerOS-SA-2021-2374)
- 670967 EulerOS Security Update for glibc (EulerOS-SA-2021-2581)
- 710069 Gentoo Linux glibc Multiple vulnerabilities (GLSA 202107-07)
- 751195 SUSE Enterprise Linux Security Update for glibc (SUSE-SU-2021:3290-1)
- 751196 SUSE Enterprise Linux Security Update for glibc (SUSE-SU-2021:3289-1)
- 751200 OpenSUSE Security Update for glibc (openSUSE-SU-2021:3291-1)
- 751212 SUSE Enterprise Linux Security Update for glibc (SUSE-SU-2021:3385-1)
- 751242 OpenSUSE Security Update for glibc (openSUSE-SU-2021:1374-1)
- 900034 CBL-Mariner Linux Security Update for glibc 2.28
- 902905 Common Base Linux Mariner (CBL-Mariner) Security Update for glibc (4243)
- 940330 AlmaLinux Security Update for glibc (ALSA-2021:4358)