Vulnerability in Glibc allows crashing of another process

A vulnerability has been identified in Glibc (CVE-2021-38604) that allows the initiation of process crashes in the system by sending specially crafted messages through the POSIX message queues API. The issue has not yet manifested in distributions, as it only exists in version 2.34, released two weeks ago.

The problem arises from improper handling of NOTIFY_REMOVED data in the mq_notify.c code, leading to a null pointer dereference and process crash. Interestingly, this issue is a consequence of an oversight during the fix of another vulnerability (CVE-2021-33574) that was addressed in Glibc version 2.34. While the first vulnerability was quite difficult to exploit and required a specific set of circumstances, launching an attack using the second issue is significantly easier.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster