CVE-2021-3998

Name
CVE-2021-3998
Description
A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.openwall.com/lists/oss-security/2022/01/24/4
MISC https://access.redhat.com/security/cve/CVE-2021-3998
MISC https://sourceware.org/bugzilla/show_bug.cgi?id=28770
MISC https://security-tracker.debian.org/tracker/CVE-2021-3998
MISC https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=ee8d5e33adb284601c00c94687bc907e10aec9bb
MISC https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=84d2d0fe20bdf94feed82b21b4d7d136db471f03
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2024633

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:* glibc >= 2.33 <= None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status