CVE-2021-27219

Updated: 2022-12-07 20:03:23.626717

Description:

An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS glib2 2.28.8 7.5 HIGH Released CLSA-2021:1623075923 2022-05-05 12:38:32
CentOS 8.4 ELS glib2 2.56.4-10 7.5 HIGH Not Vulnerable 2022-02-14 17:48:07
CentOS 8.5 ELS glib2 2.56.4-156 7.5 HIGH Not Vulnerable 2022-02-14 17:48:07
CloudLinux 6 ELS glib2 2.28.8 7.5 HIGH Released 2021-12-09 07:57:03
Oracle Linux 6 ELS glib2 2.28.8 7.5 HIGH Released 2021-12-09 07:57:03
Ubuntu 16.04 ELS glib2 2.48.2-0 7.5 HIGH Not Vulnerable 2021-12-09 07:57:03
Ubuntu 18.04 ELS glib2 2.56.4-0 7.5 HIGH Needs Triage 2023-03-02 13:00:59