The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified other impact.
| Software | From | Fixed in |
|---|---|---|
| gnu / glibc | 2.33 | 2.33.x |
| gnu / glibc | 2.32 | 2.32.x |
| fedoraproject / fedora | 33 | 33.x |
| fedoraproject / fedora | 34 | 34.x |
| netapp / e-series_santricity_os_controller | 11.0 | 11.70.1.x |
| debian / debian_linux | 10.0 | 10.0.x |