peter bassill · operator
$ cve CVE-2021-22945 JSON

CVE-2021-22945

9.1
CRITICAL · CVSS 3.1 · EPSS 6.7% (pctl 94)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS6.68% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-415
On CISA KEVno
Public exploitnone known
Published2021-09-23
Last modified2026-06-17

Affected (25)

VendorProduct
applemacos
debiandebian linux
fedoraprojectfedora
haxxlibcurl
netappcloud backup
netappclustered data ontap
netapph300e
netapph300e firmware
netapph300s
netapph300s firmware
netapph410s
netapph410s firmware
netapph500e
netapph500e firmware
netapph500s
netapph500s firmware
netapph700e
netapph700e firmware
netapph700s
netapph700s firmware
netappsolidfire baseboard management controller
netappsolidfire baseboard management controller firmware
oraclemysql server
siemenssinec ins
splunkuniversal forwarder

References

→ the Explorer  ·  watch your stack  ·  NVD