Logo
vulnerabilityCVE-2021-3700
Name
CVE-2021-3700
Source
NVD ( link)Debian ( link)
Description
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
usbredir
Patched

Vulnerability Ratings#


6.4
CVSSv31
4.4
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
0.14.0
Not Affected
yocto
scarthgap
0.13.0
Not Affected

Resolved with patches#


usbredir (yocto:kirkstone)

#
Title
Author
Resolve
1
Avoid use-after-free in serialization
Michael Hanselmann <public@hansmi.ch>
CVE-2021-3700