CVE-2021-22945: Apple macOS
Critical severity, CVSS 9.1. EPSS: 6.7% chance of exploitation in the next 30 days.
When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.
Affected products
- Apple macOS: from 12.0.0, before 12.3 (fixed in 12.3)
- Debian Debian Linux: version 11.0 only
- Fedoraproject Fedora: version 33 only; version 35 only
- Haxx Libcurl: from 7.73.0, up to and including 7.78.0
- Netapp Cloud Backup: affected versions not specified
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp h300e Firmware: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500e Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700e Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Solidfire Baseboard Management Controller Firmware: affected versions not specified
- Oracle MySQL Server: from 5.7.0, up to and including 5.7.35; from 8.0.0, up to and including 8.0.26
- Siemens Sinec Ins: before 1.0.1.1 (fixed in 1.0.1.1)
- Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only
Published 2021-09-23. Last modified 2026-06-17.