A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libgetdata | May 17, 2021 | May 6, 2021 |
| Suse | — | Upgrade python-getdataUpgrade getdata-develUpgrade libgetdata-7Upgrade libgetdata8Upgrade libfgetdata6Upgrade getdata-docUpgrade getdataUpgrade perl-getdataUpgrade libf95getdata7 | Dec 31, 2021 | May 6, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 6, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub