CVE-2021-33646: High severity centos libtar vulnerability
Published Aug 9, 2022
·Updated
Last updated 31 March 2025
Other sources
The thread() function doesn’t free a variable t->thbuf.gnulongname after allocating memory, which may cause a memory leak.
— MITRE
Affected Software
11 affected componentsFixes available
Feep Libtar<1.2.21
Huawei Openeuler=20.03-sp1
Huawei Openeuler=20.03-sp3
Huawei Openeuler=22.03
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
debian/libtar<=1.2.20-8
1.2.20-8+deb12u1~deb11u11.2.20-8+deb12u1
Openatom Openeuler=20.03-sp1
Openatom Openeuler=20.03-sp3
Openatom Openeuler=22.03
Event History
Aug 9, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Aug 10, 2022
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 25, 2022
Data Sourced
via Red Hat·05:16 AM
DescriptionSeverityAffected Software
Mar 31, 2025
Data Sourced
via Ubuntu·07:13 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·07:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-33646?
CVE-2021-33646 is classified as a medium severity vulnerability due to its potential to cause memory leaks.
2
How do I fix CVE-2021-33646?
To fix CVE-2021-33646, update to a version of libtar that is greater than 1.2.21 or apply the relevant patches if provided.
3
What systems are affected by CVE-2021-33646?
CVE-2021-33646 affects versions of libtar prior to 1.2.21 and specific releases of Huawei openEuler and Fedora.
4
What is the impact of CVE-2021-33646?
The impact of CVE-2021-33646 is primarily a memory leak, which can lead to degraded system performance over time.
5
Is CVE-2021-33646 being actively exploited?
As of now, there is no public indication that CVE-2021-33646 is being actively exploited in the wild.