First published: Tue Aug 09 2022(Updated: )
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
Credit: securities@openeuler.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libtar | <1.2.21 | |
openEuler | =20.03-sp1 | |
openEuler | =20.03-sp3 | |
openEuler | =22.03 | |
Fedora | =35 | |
Fedora | =36 | |
Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33646 is classified as a medium severity vulnerability due to its potential to cause memory leaks.
To fix CVE-2021-33646, update to a version of libtar that is greater than 1.2.21 or apply the relevant patches if provided.
CVE-2021-33646 affects versions of libtar prior to 1.2.21 and specific releases of Huawei openEuler and Fedora.
The impact of CVE-2021-33646 is primarily a memory leak, which can lead to degraded system performance over time.
As of now, there is no public indication that CVE-2021-33646 is being actively exploited in the wild.