Critical severity9.1NVD Advisory· Published Aug 10, 2022· Updated Jun 23, 2026
CVE-2021-33643
CVE-2021-33643
Description
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- osv-coords2 versions
< 1.2.20-17.el8+ 1 more
- (no CPE)range: < 1.2.20-17.el8
- (no CPE)range: < 1.2.20-3.1
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- www.openeuler.org/en/security/safety-bulletin/detail.htmlnvdBroken LinkThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/01/msg00026.htmlnvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5YSHZY753R7XW6CIKJVAWI373WW3YRRJ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7Q26QDNOJDOFYWMJWEIK5XR62M2FF6IJ/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OD4HEBSTI22FNYKOKK7W3X6ZQE6FV3XC/nvd
News mentions
0No linked articles in our index yet.