VYPR
Medium severity6.2NVD Advisory· Published Dec 19, 2022· Updated Jun 17, 2026

CVE-2021-33640

CVE-2021-33640

Description

After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • cpe:2.3:o:openatom:openeuler:20.03:sp1:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:openatom:openeuler:20.03:sp1:*:*:lts:*:*:*
    • cpe:2.3:o:openatom:openeuler:20.03:sp2:*:*:lts:*:*:*
    • cpe:2.3:o:openatom:openeuler:22.03:*:*:*:lts:*:*:*
  • Openeuler/libtarllm-create
  • openEuler/openEuler 20.03 LTS SP1v5
    Range: libtar 1.2.20-19
  • openEuler/openEuler 20.03 LTS SP3v5
    Range: libtar 1.2.20-19
  • openEuler/openEuler 22.03 LTSv5
    Range: libtar 1.2.20-21

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.