CVE-2021-38604

Updated: 2025-08-20 00:24:45.918705

Description:

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU glibc 2.34 7.5 HIGH Not Vulnerable 2023-11-08 08:36:05
CentOS 6 ELS glibc 2.12 7.5 HIGH Released CLSA-2021:1629395067 2022-05-05 12:00:37
CentOS 7 ELS glibc 2.17 7.5 HIGH Not Vulnerable 2023-09-19 09:30:30
CentOS 8.4 ELS glibc 2.28 7.5 HIGH Released CLSA-2022:1643727522 2022-02-22 14:42:09
CentOS 8.5 ELS glibc 2.28 7.5 HIGH Not Vulnerable 2022-02-22 11:49:15
CloudLinux 6 ELS glibc 2.12 7.5 HIGH Released 2022-04-07 13:06:43
Oracle Linux 6 ELS glibc 2.12 7.5 HIGH Released CLSA-2021:1634922609 2021-12-09 07:57:04
Ubuntu 16.04 ELS glibc 2.23-0 7.5 HIGH Released CLSA-2021:1635459187 2021-12-09 07:57:04
Ubuntu 18.04 ELS glibc 2.27-3 7.5 HIGH Not Vulnerable 2023-06-14 09:07:24