NULL pointer dereference in GNU C Library (glibc) - CVE-2021-38604

 

NULL pointer dereference in GNU C Library (glibc) - CVE-2021-38604

Published: August 17, 2021


Vulnerability identifier: #VU55916
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38604
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the "sysdeps/unix/sysv/linux/mq_notify.c" file within NOTIFY_REMOVED data. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

GNU C Library (glibc)
Gentoo Linux
openEuler
Fedora
SIMATIC S7-1500 TM MFP - BIOS
glibc
glibc-help
glibc-debugsource
glibc-debuginfo
glibc-locale-source
glibc-benchtests
glibc-nss-devel
libnsl
glibc-devel
glibc-all-langpacks
glibc-debugutils
nscd
glibc-common
nss_modules
sys-libs/glibc
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data

How to mitigate CVE-2021-38604

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

glibc - update to 2.28-77
glibc-help - update to 2.28-77
glibc-debugsource - update to 2.28-77
glibc-debuginfo - update to 2.28-77
glibc-locale-source - update to 2.28-77
glibc-benchtests - update to 2.28-77
glibc-nss-devel - update to 2.28-77
libnsl - update to 2.28-77
glibc-devel - update to 2.28-77
glibc-all-langpacks - update to 2.28-77
glibc-debugutils - update to 2.28-77
nscd - update to 2.28-77
glibc-common - update to 2.28-77
nss_modules - update to 2.28-77
sys-libs/glibc - update to 2.34
glibc - update to 2.34-6.fc35
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5

External References

Related Security Bulletins