CVE-2021-27186

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
10/02/2021
Last modified:
16/02/2021

Description

Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:treasuredata:fluent_bit:1.6.10:*:*:*:*:*:*:*