{"schema_version":"1.9.0","id":"CVE-2021-33574","published":"2021-05-25T22:15:10.410Z","modified":"2026-08-28T11:45:28.462345088Z","related":["ALSA-2021:4358","SUSE-SU-2021:14822-1","SUSE-SU-2021:3289-1","SUSE-SU-2021:3290-1","SUSE-SU-2021:3291-1","SUSE-SU-2021:3385-1","openSUSE-SU-2021:1374-1","openSUSE-SU-2021:3291-1","openSUSE-SU-2024:10792-1"],"details":"The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bminor/glibc","events":[{"introduced":"3de512be7ea6053255afed6154db9ee31d4e557a"},{"last_affected":"9826b03b747b841f5fc6de2054bf1ef3f5c4bdf3"}],"database_specific":{"cpe":["cpe:2.3:a:gnu:glibc:2.32:*:*:*:*:*:*:*","cpe:2.3:a:gnu:glibc:2.33:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.32"},{"last_affected":"2.32"},{"introduced":"2.33"},{"last_affected":"2.33"}],"source":"CPE_STRING"}}],"versions":["2.32","2.33","glibc-2.33","glibc-2.32","glibc-2.32.9000"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33574.json"}},{"ranges":[{"type":"GIT","repo":"https://sourceware.org/git/glibc.git","events":[{"introduced":"3de512be7ea6053255afed6154db9ee31d4e557a"},{"last_affected":"9826b03b747b841f5fc6de2054bf1ef3f5c4bdf3"}],"database_specific":{"cpe":["cpe:2.3:a:gnu:glibc:2.32:*:*:*:*:*:*:*","cpe:2.3:a:gnu:glibc:2.33:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.32"},{"last_affected":"2.32"},{"introduced":"2.33"},{"last_affected":"2.33"}],"source":"CPE_STRING"}}],"versions":["2.32","2.33","glibc-2.33","glibc-2.32","glibc-2.32.9000"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33574.json"}}],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJYYIMDDYOHTP2PORLABTOHYQYYREZDD/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBUUWUGXVILQXVWEOU7N42ICHPJNAEUP/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202107-07"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210629-0005/"},{"type":"REPORT","url":"https://sourceware.org/bugzilla/show_bug.cgi?id=27896"},{"type":"REPORT","url":"https://sourceware.org/bugzilla/show_bug.cgi?id=27896#c1"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"11.0"},{"last_affected":"11.70.1"}],"source":"CPE_RANGE","vendor_product":"netapp:e-series_santricity_os_controller"},{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10.0"},{"last_affected":"10.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}