← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-38604

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:3.04%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-476 ↗CWE-476 NULL Pointer Dereference

Affected Products & Versions

Vendor Product Affected Versions
gnu glibc all
fedoraproject fedora 35
oracle communications_cloud_native_core_binding_support_function 22.1.3
oracle communications_cloud_native_core_network_function_cloud_native_environment 22.1.0
oracle communications_cloud_native_core_network_repository_function 22.1.2, 22.2.0
oracle communications_cloud_native_core_security_edge_protection_proxy 22.1.1
oracle communications_cloud_native_core_unified_data_repository 22.2.0
oracle enterprise_operations_monitor 4.3, 4.4, 5.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.045%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-08-12T00:00:00
Published2021-08-12T15:43:34
Last Updated2025-05-30T19:48:04

LINK COPIED TO CLIPBOARD