CVE-2021-22945: Apple macOS

Critical severity, CVSS 9.1. EPSS: 6.7% chance of exploitation in the next 30 days.

When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

Affected products

  • Apple macOS: from 12.0.0, before 12.3 (fixed in 12.3)
  • Debian Debian Linux: version 11.0 only
  • Fedoraproject Fedora: version 33 only; version 35 only
  • Haxx Libcurl: from 7.73.0, up to and including 7.78.0
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp h300e Firmware: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500e Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700e Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Solidfire Baseboard Management Controller Firmware: affected versions not specified
  • Oracle MySQL Server: from 5.7.0, up to and including 5.7.35; from 8.0.0, up to and including 8.0.26
  • Siemens Sinec Ins: before 1.0.1.1 (fixed in 1.0.1.1)
  • Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only

Published 2021-09-23. Last modified 2026-06-17.