Back to Database
Status published
Medium
CVE-2021-33640
After tar_close(), libtar.c releases the memory pointed to by pointer...
Vulnerability Description
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-33640
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2021-33640&packageName=libtar
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4S4PJRCJLEAWN2EKXGLSOBTL7O57V7NC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WX5YE66CT7Y5C2HTHXSFDKQWYWYWJ2T/
More from openEuler
View All →CVE-2025-31344
The giflib open-source component has a buffer overflow vulnerability
High
7.3
CVE-2024-24899
Command injection in aops-zeus
High
7.2
CVE-2024-24898
Information Leakage in kernel
Medium
6
CVE-2024-24897
Remote command execution in A-Tune-Collector
High
8.1
CVE-2024-24892
Unauthorized RCE in migration-tools
High
8.1
Affected Vendor
openEuler
View all reports →Affected Software
openEuler 22.03 LTS, openEuler 20.03 LTS SP1, openEuler 20.03 LTS SP3
Vulnerable Versions:
libtar 1.2.20-21, libtar 1.2.20-19
Timeline
Official Publish:
December 19th, 2022
Last Modified:
April 17th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H