When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5197-1 | curl security update |
EUVD |
EUVD-2021-10073 | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*. |
Ubuntu USN |
USN-5079-1 | curl vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 09 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-06-09T14:47:23.444Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-22945
Updated: 2024-08-03T18:58:26.137Z
Status : Modified
Published: 2021-09-23T13:15:08.690
Modified: 2025-06-09T15:15:25.540
Link: CVE-2021-22945
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN