CVE-2021-3939: Free of static data in accountsservice
Last updated 25 August 2025
Other sources
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallbacklocale variable, pointing to static storage, to be freed, in the userchangelanguageauthorizedcb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Ubuntu-specific modifications to accountsservice vulnerability?
The vulnerability ID is CVE-2021-3939.
What is the severity level of CVE-2021-3939?
The severity level of CVE-2021-3939 is high with a value of 7.8.
What is the affected software for CVE-2021-3939?
The affected software for CVE-2021-3939 is accountsservice on Ubuntu and Canonical Accountsservice.
How can I fix CVE-2021-3939?
To fix CVE-2021-3939, update the accountsservice package to the recommended versions listed in the Ubuntu or Debian repositories.
Where can I find more information about CVE-2021-3939?
More information about CVE-2021-3939 can be found in the references: [link1], [link2], [link3].