High severity8.1NVD Advisory· Published Mar 10, 2021· Updated Jun 17, 2026
CVE-2021-21772
CVE-2021-21772
Description
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- 3MF Consortium/lib3mfdescription
- Range: <2.0.0
Patches
Vulnerability mechanics
References
7- talosintelligence.com/vulnerability_reports/TALOS-2020-1226nvdExploitThird Party Advisory
- www.talosintelligence.com/vulnerability_reports/TALOS-2021-1226nvdExploitThird Party Advisory
- security.gentoo.org/glsa/202208-01nvdThird Party Advisory
- www.debian.org/security/2021/dsa-4887nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IHMMHD2EOMIVJ7EKZTJJMX4C7E6ZRWDL/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NPBS642OYVA6DUKK3HZHEINVWEDZSMEU/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WDGGB65YBQL662M3MOBNNJJNRNURW4TG/nvd
News mentions
0No linked articles in our index yet.