CVE-2021-35942 - CVE House
Back to Database
Status published Unknown CVE-2021-35942

The wordexp function in the GNU C Library (aka glibc)...

Vulnerability Description

The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have been used to ensure correct calculations.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-35942

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

glibc, active iq unified manager, e-series santricity os controller, hci management node, ontap select deploy administration utility, solidfire, debian linux
Vulnerable Versions:
0, 11.0, 10.0

Timeline

Official Publish: July 22nd, 2021
Last Modified: February 13th, 2026
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.