CVE-2021-36088: Double Free
Published Jul 1, 2021
·Updated
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7,4 has a double free in flbfree (called from flbparserjsondo and flbparserdo).
Other sources
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flbfree (called from flbparserjsondo and flbparserdo).
— MITRE
Affected Software
1 affected component
Treasuredata Fluent Bit>=1.7.0<=1.7.4
Remediation
Patch Available
Patch Available
Event History
Jul 1, 2021
CVE Published
via MITRE·02:50 AM
Data Sourced
via MITRE·02:50 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-36088?
CVE-2021-36088 has been classified with a high severity due to the presence of a double free vulnerability.
2
How do I fix CVE-2021-36088?
To fix CVE-2021-36088, you should upgrade Fluent Bit to version 1.7.5 or later.
3
What versions of Fluent Bit are affected by CVE-2021-36088?
Fluent Bit versions from 1.7.0 to 1.7.4 are affected by CVE-2021-36088.
4
What are the potential impacts of CVE-2021-36088?
The double free vulnerability in CVE-2021-36088 could lead to crashes or unexpected behavior in Fluent Bit.
5
How can I determine if my installation is vulnerable to CVE-2021-36088?
You can determine if your installation is vulnerable by checking the version of Fluent Bit you are currently using.