A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libgetdata | May 17, 2021 | May 6, 2021 |
| Suse | — | Upgrade getdata-docUpgrade libf95getdata7Upgrade libfgetdata6Upgrade libgetdata-7Upgrade libgetdata8Upgrade getdataUpgrade perl-getdataUpgrade python-getdataUpgrade getdata-devel | Dec 31, 2021 | May 6, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 6, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub