VYPR
High severity7.8NVD Advisory· Published Nov 17, 2021· Updated Jun 17, 2026

CVE-2021-3939

CVE-2021-3939

Description

Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:canonical:accountsservice:*:*:*:*:*:*:*:*
    Range: >=0.6.55-0ubuntu12\~20.04,<0.6.55-0ubuntu12\~20.05
  • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:21.04:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:21.10:*:*:*:*:*:*:*
  • Range: 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1
  • Ubuntu/accountsservicev5
    Range: 0.6.55-0ubuntu12~20.04

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.