CVE-2021-22945: Double Free
curl. Multiple issues were addressed by updating to curl version 7.79.1.
Other sources
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it again.
Credit
Affected Software
Remediation
Patch Available
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-22633
- CVE-2022-22669
- CVE-2022-22665
- CVE-2022-22630
- CVE-2022-22631
- CVE-2022-22625
- CVE-2022-22648
- CVE-2022-22626
- CVE-2022-22627
- CVE-2022-22597
- CVE-2022-22616
- CVE-2022-22663
- CVE-2022-26691
- CVE-2021-22946
- CVE-2021-22947
- CVE-2021-22945
- CVE-2022-22643
- CVE-2022-22657
- CVE-2022-22664
- CVE-2021-30977
- CVE-2022-22611
- CVE-2022-22612
- CVE-2022-46706
- CVE-2022-22661
- CVE-2022-22641
- CVE-2022-22613
- CVE-2022-22614
- CVE-2022-22615
- CVE-2022-22632
- CVE-2022-22638
- CVE-2022-22640
- CVE-2021-30946
- CVE-2021-36976
- CVE-2022-21658
- CVE-2022-22647
- CVE-2022-22656
- CVE-2022-22672
- CVE-2022-22644
- CVE-2022-26690
- CVE-2022-26688
- CVE-2022-22617
- CVE-2022-22609
- CVE-2022-22650
- CVE-2022-22655
- CVE-2022-22600
- CVE-2022-22599
- CVE-2022-22651
- CVE-2022-22639
- CVE-2022-22660
- CVE-2022-22621
- CVE-2021-4136
- CVE-2021-4166
- CVE-2021-4173
- CVE-2021-4187
- CVE-2021-4192
- CVE-2021-4193
- CVE-2021-46059
- CVE-2022-0128
- CVE-2022-0156
- CVE-2022-0158
- CVE-2021-30918
- CVE-2022-22662
- CVE-2022-22610
- CVE-2022-22624
- CVE-2022-22628
- CVE-2022-22629
- CVE-2022-22637
- CVE-2022-22668
- CVE-2022-22582
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-22945.
What is the severity of CVE-2021-22945?
The severity of CVE-2021-22945 is not mentioned in the provided information.
What is the affected software for CVE-2021-22945?
The affected software for CVE-2021-22945 includes curl versions <= 7.73.0 and 7.78.0, as well as macOS Monterey version up to 12.3.
How can I fix CVE-2021-22945?
To fix CVE-2021-22945, update your curl installation to version 7.79.1 or later, or update macOS Monterey to a version later than 12.3.
Where can I find more information about CVE-2021-22945?
You can find more information about CVE-2021-22945 on the following references: [here](https://support.apple.com/en-us/HT213183), [here](https://curl.se/docs/CVE-2021-22945.html), and [here](https://github.com/curl/curl/commit/43157490a5054bd24256fe12876931e8abc9df49).