CVE-2021-20234: Medium severity libzmq5 vulnerability
A flaw was found in zeromq before 4.3.3. When a pipe processes a delimiter and is already not in active state but still has an unfinished message, the message is leaked causing a crash.
References:
https://github.com/zeromq/libzmq/pull/3918 https://github.com/zeromq/libzmq/security/advisories/GHSA-wfr2-29gj-5w87 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22037 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22123
Other sources
An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a client that connects to multiple malicious or compromised servers to crash. The highest threat from this vulnerability is to system availability.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20234?
CVE-2021-20234 is an uncontrolled resource consumption (memory leak) vulnerability in the ZeroMQ client.
What is the severity of CVE-2021-20234?
The severity of CVE-2021-20234 is medium with a CVSS score of 6.5.
Which software versions are affected by CVE-2021-20234?
Versions before 4.3.3 of the ZeroMQ client are affected.
How does CVE-2021-20234 impact system availability?
CVE-2021-20234 can cause a system to crash if a client connects to multiple malicious or compromised servers.
How can I fix CVE-2021-20234?
To fix CVE-2021-20234, upgrade to version 4.3.3-1 of the ZeroMQ client.