CVE-2021-3420

A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 80.44%
Affected Products (NVD)
VendorProductVersion
newlib_projectnewlib
𝑥
< 4.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
newlib
bookworm
3.3.0-1.3+deb12u1
fixed
bullseye
ignored
buster
no-dsa
sid
4.4.0.20231231-4
fixed
stretch
no-dsa
trixie
4.4.0.20231231-4
fixed
picolibc
bookworm
1.8-1
fixed
bullseye
1.5.1-2
ignored
buster
no-dsa
sid
1.8.8-2
fixed
stretch
no-dsa
trixie
1.8.8-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
newlib
bionic
needed
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needed
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
trusty
dne
xenial
needed
gcc-snapshot
bionic
not-affected
focal
not-affected
jammy
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
trusty
ignored
xenial
not-affected