CVE-2021-44538: Buffer Overflow
The olmsessiondescribe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olmsessiondescribe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.
Other sources
Thunderbird users who use the Matrix chat protocol were vulnerable to a buffer overflow in libolm, that an attacker may trigger by a crafted sequence of messages. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-44538?
CVE-2021-44538 is a vulnerability in the Matrix libolm library that allows attackers to trigger a buffer overflow.
Which software products are affected by CVE-2021-44538?
CVE-2021-44538 affects Mozilla Thunderbird, Matrix Element, Matrix Javascript SDK, Schildi Schildichat, Cinny Project Cinny, and Debian Linux.
What is the severity of CVE-2021-44538?
CVE-2021-44538 has a severity rating of 9.8 (Critical).
How can I fix CVE-2021-44538?
To fix CVE-2021-44538, users should update to the latest versions of the affected software, such as Mozilla Thunderbird 91.4.1 and Matrix Element 1.9.7.
Where can I find more information about CVE-2021-44538?
More information about CVE-2021-44538 can be found in the Mozilla bugzilla and security advisories, as well as the Matrix libolm GitLab repository.