VulnerabilityModified
CVE-2021-43618
GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.
HIGH 7.5EPSS 3.71%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.71% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- gmplib/gmp · debian/debian linux · netapp/active iq unified manager · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware · netapp/h410c firmware
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2022/Oct/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/10/13/3Mailing List, Third Party Advisory
- https://bugs.debian.org/994405Mailing List, Third Party Advisory
- https://gmplib.org/list-archives/gmp-bugs/2021-September/005077.htmlExploit, Third Party Advisory
- https://gmplib.org/repo/gmp-6.2/rev/561a9c25298ePatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00001.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202309-13
- https://security.netapp.com/advisory/ntap-20221111-0001/Third Party Advisory
- http://seclists.org/fulldisclosure/2022/Oct/8Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2022/10/13/3Mailing List, Third Party Advisory
- https://bugs.debian.org/994405Mailing List, Third Party Advisory
- https://gmplib.org/list-archives/gmp-bugs/2021-September/005077.htmlExploit, Third Party Advisory
- https://gmplib.org/repo/gmp-6.2/rev/561a9c25298ePatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00001.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202309-13
- https://security.netapp.com/advisory/ntap-20221111-0001/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.