Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-33574

Опубликовано: 21 мая 2021
Источник: redhat
CVSS3: 5.9

Описание

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.

The mq_notify function in the GNU C Library (aka glibc) has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.

Отчет

In order to mount a minimal attack using this flaw, an attacker needs many pre-requisites to be able to even crash a program using this mq_notify bug:

  1. The program call to mq_notify needs to be controlled by the attacker
  2. The program must provide attributes to control creation of the notification thread in mq_notify
  3. The program must have the race condition where it may potentially destroy the notification thread attributes before the notification thread is created
  4. The program must set CPU affinity of the notification thread to actually cause the use-after-free dereference There are no known applications that have all these pre-requisites.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6compat-glibcOut of support scope
Red Hat Enterprise Linux 6glibcOut of support scope
Red Hat Enterprise Linux 7compat-glibcOut of support scope
Red Hat Enterprise Linux 7glibcOut of support scope
Red Hat Enterprise Linux 9glibcNot affected
Red Hat Enterprise Linux 8glibcFixedRHSA-2021:435809.11.2021
Red Hat Enterprise Linux 8glibcFixedRHSA-2021:435809.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1965408glibc: mq_notify does not handle separately allocated thread attributes

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.

CVSS3: 9.8
nvd
около 4 лет назад

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.

CVSS3: 9.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 9.8
debian
около 4 лет назад

The mq_notify function in the GNU C Library (aka glibc) versions 2.32 ...

suse-cvrf
больше 3 лет назад

Security update for glibc

5.9 Medium

CVSS3