First published: Tue Oct 26 2021(Updated: )
Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Credit: chrome-cve-admin@google.com Clément Lecigne Google TAGSamuel Groß Google Project Zero chrome-cve-admin@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | <=90.0.4430.212-1~deb10u1 | 116.0.5845.180-1~deb11u1 118.0.5993.70-1~deb11u1 116.0.5845.180-1~deb12u1 118.0.5993.70-1~deb12u1 118.0.5993.70-1 |
Google Chrome | <95.0.4638.69 | |
Fedoraproject Fedora | =34 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Google Chromium V8 | ||
Google Chrome | <95.0.4638.69 | 95.0.4638.69 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this vulnerability is CVE-2021-38003.
The title of this vulnerability is Google Chromium V8 Memory Corruption Vulnerability.
Web browsers that utilize Chromium, including Google Chrome and Microsoft Edge, are affected by this vulnerability.
CVE-2021-38003 has a severity rating of 8.8 (high).
Google Chrome versions up to 95.0.4638.69 are affected by CVE-2021-38003.
Fedora version 34 is affected by CVE-2021-38003.
Debian Linux version 10.0 is affected by CVE-2021-38003.
Debian Linux version 11.0 is affected by CVE-2021-38003.
To fix CVE-2021-38003 on Google Chrome, update to versions 95.0.4638.69 or newer.
To fix CVE-2021-38003 on Fedora, apply the necessary updates mentioned in the reference link.
To fix CVE-2021-38003 on Debian Linux 10, update the chromium package to version 90.0.4430.212-1~deb10u1 or newer.
To fix CVE-2021-38003 on Debian Linux 11, update the chromium package to version 116.0.5845.180-1~deb11u1 or newer.