CVE-2021-38604

Related Vulnerabilities: CVE-2021-38604  

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

Description

The MITRE CVE dictionary describes this issue as:

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

Additional Information

  • Bugzilla 1993517: CVE-2021-38604 glibc: NULL pointer dereference in helper_thread() in sysdeps/unix/sysv/linux/mq_notify.c because it mishandles certain NOTIFY_REMOVED data
  • CWE-476: NULL Pointer Dereference
  • FAQ: Frequently asked questions about CVE-2021-38604