PT-2021-4562 · Klibc+4 · Klibc+4

Ben Hutchings

·

Published

2021-04-28

·

Updated

2023-11-07

·

CVE-2021-31873

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions klibc versions prior to 2.0.9
Description The issue is related to the malloc() function in the klibc library, which may result in an integer overflow and a subsequent heap buffer overflow. This could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 2.0.9, update to version 2.0.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the malloc() function until a patch is available.

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1803
ALT-PU-2022-1761
BDU:2021-05232
CVE-2021-31873
DLA-2695-1
USN-5379-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Ubuntu
Klibc