Fiche vulnérabilité
CVE-2021-27218 : faille élevée gnome glib (CVSS 7.5)
Description
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 15 févr. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- gnome glib
- fedoraproject fedora
- netapp active iq unified manager
- netapp cloud backup
- netapp e-series performance analyzer
- broadcom brocade fabric operating system firmware
- debian debian linux
Références
- Fiche CVE-2021-27218 sur le NVD (NIST)
- gitlab.gnome.org/GNOME/glib/-/merge_requests/1942
- gitlab.gnome.org/GNOME/glib/-/merge_requests/1944
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.debian.org/debian-lts-announce/2022/06/msg00006.html
- lists.fedoraproject.org/archives/list/package…
- lists.fedoraproject.org/archives/list/package…
- security.gentoo.org/glsa/202107-13
- security.netapp.com/advisory/ntap-20210319-0004/