CVE-2021-33586

MEDIUM

InspIRCd <3.10.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
https://docs.inspircd.org/security/2021-01/
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202107-22

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-732
Status published
Products (1)
inspircd/inspircd 3.8.0 - 3.10.0
Published May 27, 2021
Tracked Since Feb 18, 2026