Bugzilla – Bug 1186489
VUL-0: CVE-2021-33574: glibc: mq_notify() has a use-after-free
Last modified: 2022-11-25 09:56:10 UTC
CVE-2021-33574 The mq_notify function in the GNU C Library (aka glibc) through 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-33574 http://www.cvedetails.com/cve/CVE-2021-33574/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33574 https://sourceware.org/bugzilla/show_bug.cgi?id=27896
This is an autogenerated message for OBS integration: This bug (1186489) was mentioned in https://build.opensuse.org/request/show/899091 Factory / glibc
seems affect all our glibc versions after review.
see also bug 1189426
andreas, can you submit fixed packages? at least SUSE:SLE-15:Update/glibc SUSE:SLE-12-SP4:Update/glibc SUSE:SLE-11-SP3:Update/glibc SUSE:SLE-11-SP1:Update/glibc for non-ltss
SUSE-SU-2021:14822-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1186489,1187911 CVE References: CVE-2021-33574,CVE-2021-35942 JIRA References: Sources used: SUSE Linux Enterprise Server 11-SP4-LTSS (src): glibc-2.11.3-17.110.37.1 SUSE Linux Enterprise Point of Sale 11-SP3 (src): glibc-2.11.3-17.110.37.1 SUSE Linux Enterprise Debuginfo 11-SP4 (src): glibc-2.11.3-17.110.37.1 SUSE Linux Enterprise Debuginfo 11-SP3 (src): glibc-2.11.3-17.110.37.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:3291-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1186489,1187911 CVE References: CVE-2021-33574,CVE-2021-35942 JIRA References: Sources used: SUSE MicroOS 5.1 (src): glibc-2.31-9.3.2 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): glibc-2.31-9.3.2, glibc-utils-src-2.31-9.3.2 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): glibc-2.31-9.3.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:3290-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1186489 CVE References: CVE-2021-33574 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): glibc-2.22-114.15.1 SUSE OpenStack Cloud 9 (src): glibc-2.22-114.15.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): glibc-2.22-114.15.1 SUSE Linux Enterprise Server for SAP 12-SP4 (src): glibc-2.22-114.15.1 SUSE Linux Enterprise Server 12-SP5 (src): glibc-2.22-114.15.1 SUSE Linux Enterprise Server 12-SP4-LTSS (src): glibc-2.22-114.15.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:3291-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1186489,1187911 CVE References: CVE-2021-33574,CVE-2021-35942 JIRA References: Sources used: openSUSE Leap 15.3 (src): glibc-2.31-9.3.2, glibc-utils-src-2.31-9.3.2
SUSE-SU-2021:3289-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1117993,1186489,1187911 CVE References: CVE-2021-33574,CVE-2021-35942 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 8 (src): glibc-2.22-116.1 SUSE OpenStack Cloud 8 (src): glibc-2.22-116.1 SUSE Linux Enterprise Server for SAP 12-SP3 (src): glibc-2.22-116.1 SUSE Linux Enterprise Server 12-SP3-LTSS (src): glibc-2.22-116.1 SUSE Linux Enterprise Server 12-SP3-BCL (src): glibc-2.22-116.1 SUSE Linux Enterprise Server 12-SP2-BCL (src): glibc-2.22-116.1 HPE Helion Openstack 8 (src): glibc-2.22-116.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:3385-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1186489,1187911 CVE References: CVE-2021-33574,CVE-2021-35942 JIRA References: Sources used: SUSE MicroOS 5.0 (src): glibc-2.26-13.59.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise Server for SAP 15 (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise Server 15-LTSS (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise Module for Development Tools 15-SP2 (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise Module for Basesystem 15-SP2 (src): glibc-2.26-13.59.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE Enterprise Storage 6 (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 SUSE CaaS Platform 4.0 (src): glibc-2.26-13.59.1, glibc-utils-src-2.26-13.59.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:1374-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1186489,1187911 CVE References: CVE-2021-33574,CVE-2021-35942 JIRA References: Sources used: openSUSE Leap 15.2 (src): glibc-2.26-lp152.26.9.1, glibc-testsuite-src-2.26-lp152.26.9.1, glibc-utils-src-2.26-lp152.26.9.1
seems done