{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2021-22945","assignerOrgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","assignerShortName":"hackerone","dateUpdated":"2025-06-09T14:47:23.444Z","dateReserved":"2021-01-06T00:00:00.000Z","datePublished":"2021-09-23T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"36234546-b8fa-4601-9d6f-f4e334aa8ea1","shortName":"hackerone","dateUpdated":"2022-12-19T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*."}],"affected":[{"vendor":"n/a","product":"https://github.com/curl/curl","versions":[{"version":"curl 7.73.0 to and including 7.78.0","status":"affected"}]}],"references":[{"url":"https://hackerone.com/reports/1269242"},{"name":"FEDORA-2021-fc96a3a749","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"url":"https://security.netapp.com/advisory/ntap-20211029-0003/"},{"name":"FEDORA-2021-1d24845e93","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf"},{"url":"https://support.apple.com/kb/HT213183"},{"name":"20220314 APPLE-SA-2022-03-14-4 macOS Monterey 12.3","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2022/Mar/29"},{"name":"DSA-5197","tags":["vendor-advisory"],"url":"https://www.debian.org/security/2022/dsa-5197"},{"name":"GLSA-202212-01","tags":["vendor-advisory"],"url":"https://security.gentoo.org/glsa/202212-01"}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"Double Free (CWE-415)","cweId":"CWE-415"}]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T18:58:26.137Z"},"title":"CVE Program Container","references":[{"url":"https://hackerone.com/reports/1269242","tags":["x_transferred"]},{"name":"FEDORA-2021-fc96a3a749","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RWLEC6YVEM2HWUBX67SDGPSY4CQB72OE/"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","tags":["x_transferred"]},{"url":"https://security.netapp.com/advisory/ntap-20211029-0003/","tags":["x_transferred"]},{"name":"FEDORA-2021-1d24845e93","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APOAK4X73EJTAPTSVT7IRVDMUWVXNWGD/"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf","tags":["x_transferred"]},{"url":"https://support.apple.com/kb/HT213183","tags":["x_transferred"]},{"name":"20220314 APPLE-SA-2022-03-14-4 macOS Monterey 12.3","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2022/Mar/29"},{"name":"DSA-5197","tags":["vendor-advisory","x_transferred"],"url":"https://www.debian.org/security/2022/dsa-5197"},{"name":"GLSA-202212-01","tags":["vendor-advisory","x_transferred"],"url":"https://security.gentoo.org/glsa/202212-01"}]},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-415","lang":"en","description":"CWE-415 Double Free"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":9.1,"attackVector":"NETWORK","baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-03-28T15:53:40.610696Z","id":"CVE-2021-22945","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-06-09T14:47:23.444Z"}}]}}