CVE-2021-30535

NameCVE-2021-30535
DescriptionDouble free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs990079

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
chromium (PTS)stretch (security), stretch73.0.3683.75-1~deb9u1vulnerable
buster89.0.4389.114-1~deb10u1vulnerable
buster (security)90.0.4430.212-1~deb10u1vulnerable
bookworm, sid, bullseye90.0.4430.212-1vulnerable
icu (PTS)stretch (security), stretch57.1-6+deb9u4fixed
buster, buster (security)63.1-6+deb10u1vulnerable
bookworm, sid, bullseye67.1-7fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
chromiumsourcestretch(unfixed)end-of-life
chromiumsource(unstable)(unfixed)990079
icusourcestretch(not affected)
icusource(unstable)67.1-7

Notes

[stretch] - chromium <end-of-life> (see DSA 4562)
[stretch] - icu <not-affected> (Vulnerable code not present)
https://bugs.chromium.org/p/chromium/issues/detail?id=1194899 (restricted)
Bugfix: https://github.com/unicode-org/icu/pull/1698/commits/e450fa50fc242282551f56b941dc93b9a8a0bcbb
Backports: https://chromium-review.googlesource.com/c/chromium/deps/icu/+/2842864

Search for package or bug name: Reporting problems