CVE-2021-30560: Use after free in Blink XSLT
Published Jun 12, 2021
·Updated
Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit
Nick Wellnhofer
Affected Software
11 affected componentsFixes available
rubygems/nokogiri<1.13.2
1.13.2
debian/chromium<=90.0.4430.212-1~deb10u1
116.0.5845.180-1~deb11u1119.0.6045.123-1~deb11u1116.0.5845.180-1~deb12u1119.0.6045.123-1~deb12u1119.0.6045.123-1
debian/libxslt<=1.1.32-2.2~deb10u1
1.1.32-2.2~deb10u21.1.34-4+deb11u11.1.35-1
Google Chrome<91.0.4472.164
91.0.4472.164
Google Chrome<91.0.4472.164
Xmlsoft Libxslt<1.1.35
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Splunk Universal Forwarder>=8.2.0<8.2.12
Splunk Universal Forwarder>=9.0.0<9.0.6
Splunk Universal Forwarder=9.1.0
Remediation
Patch Available
Event History
Jun 12, 2021
CVE Published
12:00 AM
Aug 3, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 24, 2022
Advisory Published
07:09 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is CVE-2021-30560?
CVE-2021-30560 is a vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page in Google Chrome prior to 91.0.4472.164.
2
How severe is CVE-2021-30560?
CVE-2021-30560 has a severity rating of 8.8 out of 10, indicating a high severity.
3
How does CVE-2021-30560 affect Google Chrome?
CVE-2021-30560 affects Google Chrome versions prior to 91.0.4472.164.
4
How does CVE-2021-30560 affect libxslt?
CVE-2021-30560 affects libxslt versions up to 1.1.35.
5
How do I fix CVE-2021-30560?
To fix CVE-2021-30560, update Google Chrome to version 91.0.4472.164 or later and libxslt to version 1.1.35 or later.