NULL Pointer Dereference in GNU C Library Affects Glibc Products
CVE-2021-38604
7.5HIGH
What is CVE-2021-38604?
A vulnerability in the GNU C Library (glibc), specifically in the 'librt' component, stems from improper handling of certain NOTIFY_REMOVED data within the mq_notify function. This issue can lead to a NULL pointer dereference, potentially enabling attackers to exploit the flaw. The vulnerability was introduced as a byproduct of a previous security fix (CVE-2021-33574), and affects multiple systems using glibc versions up to 2.34, leading to stability and security concerns.