HIGH · 7.5

CVE-2021-38604

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was ...

Vulnerability Description

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
GnuGlibc<= 2.34
FedoraprojectFedora35
OracleCommunications Cloud Native Core Binding Support Function22.1.3
OracleCommunications Cloud Native Core Network Function Cloud Native Environment22.1.0
OracleCommunications Cloud Native Core Network Repository Function22.1.2
OracleCommunications Cloud Native Core Security Edge Protection Proxy22.1.1
OracleCommunications Cloud Native Core Unified Data Repository22.2.0
OracleEnterprise Operations Monitor4.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-38604?

CVE-2021-38604 is a vulnerability with a CVSS score of 7.5 (HIGH). In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was ...

How severe is CVE-2021-38604?

CVE-2021-38604 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-38604?

Check the references section above for vendor advisories and patch information. Affected products include: Gnu Glibc, Fedoraproject Fedora, Oracle Communications Cloud Native Core Binding Support Function, Oracle Communications Cloud Native Core Network Function Cloud Native Environment, Oracle Communications Cloud Native Core Network Repository Function.