NULL Pointer Dereference in GNU C Library Affects Glibc Products
CVE-2021-38604
7.5HIGH
Summary
A vulnerability in the GNU C Library (glibc), specifically in the 'librt' component, stems from improper handling of certain NOTIFY_REMOVED data within the mq_notify function. This issue can lead to a NULL pointer dereference, potentially enabling attackers to exploit the flaw. The vulnerability was introduced as a byproduct of a previous security fix (CVE-2021-33574), and affects multiple systems using glibc versions up to 2.34, leading to stability and security concerns.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved