Advisories ยป MGASA-2021-0404

Updated glibc packages fix security issue

Publication date: 14 Aug 2021
Modification date: 17 Aug 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-38604

Description

The recent fix for CVE-2021-33574 released in MGASA-2021-0308 introduced
a NULL pointer dereference because mq_notify.c mishandles certain
NOTIFY_REMOVED data, that will result in segmentation fault.
This update adds the missing NULL pointer check to resolve this issue
(CVE-2021-38604).
                

References

SRPMS

8/core