CVE-2021-38604 - log back

CVE-2021-38604 edited at 13 Aug 2021 15:03:57
Description
- In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
+ In librt in the GNU C Library (aka glibc) in version 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
CVE-2021-38604 edited at 12 Aug 2021 22:05:12
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Denial of service
Description
+ In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
References
+ https://sourceware.org/bugzilla/show_bug.cgi?id=28213
+ https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=b805aebd42364fe696e417808a700fdb9800c9e8
CVE-2021-38604 created at 12 Aug 2021 22:03:57
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes