CVE-2021-22945
PoC —CVSS 3.1
9.1 critical
EPSS
7%p94
Published
()
Modified
Description
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
- Vendors
- haxxfedoraprojectnetapporacleapplesiemensdebiansplunk
- Products
- libcurl, fedora, cloud backup, clustered data ontap, mysql server, h300s firmware, h500s firmware, h700s firmware, h300e firmware, h500e firmware, h700e firmware, h410s firmware
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.