CVE-2021-33929: Buffer Overflow
A flaw was found in libsolv. A buffer overflow vulnerability in the pooldisabledsolvable function allows attackers to cause a denial of service. The highest threat from this vulnerability is to system availability.
Other sources
Buffer overflow vulnerability in function pooldisabledsolvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-33929.
What is the title of the vulnerability?
The title of the vulnerability is "Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7...".
What is the severity of CVE-2021-33929?
The severity of CVE-2021-33929 is high.
What is the highest threat from CVE-2021-33929?
The highest threat from CVE-2021-33929 is to system availability.
What software is affected by CVE-2021-33929?
The affected software is libsolv version 0.7.16-3.el8_4, libsolv version 0.7.22-1.el7, libsolv version 0.7.22-1.el8, and IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10.
How do I fix CVE-2021-33929?
To fix CVE-2021-33929, apply the appropriate patches or updates provided by the software vendors. For IBM QRadar SIEM, you can download the patches from the IBM support website.