CVE-2021-27218: Integer Overflow
An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If gbytearraynewtake() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 232, causing unintended length truncation.
Other sources
GNOME GLib is vulnerable to a denial of service, caused by an error when invoking gbytearraynewtake() with a buffer of 4GB or more on a 64-bit platform. An attacker could exploit this vulnerability to cause unintended length truncation.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-27218?
CVE-2021-27218 is a vulnerability in GNOME GLib that allows for denial of service attacks due to unintended length truncation.
What is the severity of CVE-2021-27218?
CVE-2021-27218 has a severity level of high.
How does CVE-2021-27218 affect GNOME GLib?
CVE-2021-27218 affects GNOME GLib versions before 2.66.7 and 2.67.x before 2.67.4.
What is the remedy for CVE-2021-27218?
The remedy for CVE-2021-27218 is to update affected software to versions 2.66.7 or 2.67.4.
Is IBM QRadar SIEM affected by CVE-2021-27218?
Yes, IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10 are affected by CVE-2021-27218.