CRITICAL 9.1 Microsoft

CVE-2021-35942

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted crafted pattern potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.

Microsoft Security Update 2021-Jul: The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted crafted pattern potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.

Affected Products

References

Published: 2021-07-13 · Source: Microsoft · Feed updated: 2026-10-01
This critical severity vulnerability with a CVSS score of 9.1 was published on 2021-07-13 via Microsoft. Affected: cm1 glibc 2.28-19 on CBL Mariner 1.0.

Risk Timeline

CVE Disclosed2021-07-13 · 1905 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2021-33909 PoCfs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not proHIGH7.8
CVE-2021-35039kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature VerificaHIGH7.8
CVE-2021-37576arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpcHIGH7.8
CVE-2021-32740Regular Expression Denial of Service in Addressable templatesHIGH7.5
CVE-2021-32761Integer overflow issues with *BIT commands on 32-bit systemsHIGH7.5
CVE-2021-36222ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT KeHIGH7.5
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.