CVE-2021-38604
In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
- Gnu Glibc
- ≤ 2.34
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 3.0% (86th percentile)
- Weakness
- CWE-476
- NVD status
- Modified
- Published
- 2021-08-12
CVE-2021-38604 at NVD
No indexed exploits for CVE-2021-38604 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-38604 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.