Improper control of a resource through its lifetime in Google Chromium - CVE-2021-4100
Published: December 13, 2021 / Updated: December 15, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper control of object lifetime in ANGLE in Google Chrome. A remote attacker can trick the victim to visit a specially crafted webpage, trigger a stack-based buffer overflow and execute arbitrary code on the system.
Affected software
Google Chrome
Microsoft Edge
Gentoo Linux
Fedora
chromium
chromium (Debian package)
How to mitigate CVE-2021-4100
Google Chrome - update to 96.0.4664.110
Microsoft Edge - update to 96.0.1054.57
chromium - addressed in versions 96.0.4664.110-2.el8, 96.0.4664.110-2.fc34, 96.0.4664.110-2.fc35, 96.0.4664.110-3.fc34, 96.0.4664.110-3.fc35
chromium (Debian package) - update to 97.0.4692.71-0.1~deb11u1
External References
Related Security Bulletins
- Multiple vulnerabilities in Google Chrome
- Multiple vulnerabilities in Microsoft Edge
- Debian update for chromium
- Gentoo update for Chromium, Google Chrome
- Fedora 34 update for chromium
- Fedora 35 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora 35 update for chromium
- Fedora 34 update for chromium