CVE-2021-27645: Double Free
Last updated 24 July 2024
Other sources
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-27645.
What is the severity level of CVE-2021-27645?
The severity level of CVE-2021-27645 is low with a score of 2.5.
What software is affected by CVE-2021-27645?
The GNU C Library (glibc) versions 2.29 through 2.33, Fedora versions 33 and 34, and Debian Linux version 10.0 are affected by CVE-2021-27645.
What is the impact of CVE-2021-27645?
CVE-2021-27645 may lead to a crash in the nameserver caching daemon (nscd), potentially resulting in degraded service or Denial of Service on the local system.
Are there any references available for CVE-2021-27645?
Yes, you can find references for CVE-2021-27645 [here](https://lists.debian.org/debian-lts-announce/2022/10/msg00021.html), [here](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LZNT6KTMCCWPWXEOGSHD3YLYZKUGMH5/), and [here](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I7TS26LIZSOBLGJEZMJX4PXT5BQDE2WS/).