CVE-2021-20236

CRITICAL

Zeromq < 4.3.3 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buffer overflow on the server by sending crafted topic subscription requests and then unsubscribing. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1921976

Scores

CVSS v3 9.8
EPSS 0.0032
EPSS Percentile 54.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120 CWE-787
Status published
Products (4)
fedoraproject/fedora 33
redhat/ceph_storage 2.0
redhat/enterprise_linux 7.0
zeromq/zeromq < 4.3.3
Published May 28, 2021
Tracked Since Feb 18, 2026