VYPR
Critical severity9.1NVD Advisory· Published Aug 10, 2022· Updated Jun 23, 2026

CVE-2021-33643

CVE-2021-33643

Description

An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • osv-coords2 versions
    < 1.2.20-17.el8+ 1 more
    • (no CPE)range: < 1.2.20-17.el8
    • (no CPE)range: < 1.2.20-3.1
  • cpe:2.3:a:feep:libtar:*:*:*:*:*:*:*:*
    Range: <1.2.21
  • cpe:2.3:o:openatom:openeuler:20.03:sp1:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:openatom:openeuler:20.03:sp1:*:*:lts:*:*:*
    • cpe:2.3:o:openatom:openeuler:20.03:sp3:*:*:lts:*:*:*
    • cpe:2.3:o:openatom:openeuler:22.03:*:*:*:lts:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.