Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34950.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-34950
Upstream
  • CVE-2021-33640
Published
2022-12-19T16:15:10Z
Modified
2026-04-21T04:27:40.023983Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2021-33640 affecting package libtar for versions less than 1.2.20-11
Details

After tarclose(), libtar.c releases the memory pointed to by pointer t. After tarclose() is called in the list() function, it continues to use pointer t: freelonglinklongname(t->th_buf) . As a result, the released memory is used (use-after-free).

References

Affected packages

Azure Linux:3 / libtar

Package

Name
libtar
Purl
pkg:rpm/azure-linux/libtar

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.20-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34950.json"