CVE-2021-3782Patch(wayland / wayland)

LOWCVSS 6.6 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch wayland wayland systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An internal reference count is held on the buffer pool, incremented every time a new buffer is created from the pool. The reference count is maintained as an int; on LP64 systems this can cause the reference count to overflow if the client creates a large number of wl_shm buffer objects, or if it can coerce the server to create a large number of external references to the buffer storage. With the reference count overflowing, a use-after-free can be constructed on the wl_shm_pool tracking structure, where values may be incremented or decremented; it may also be possible to construct a limited oracle to leak 4 bytes of server-side memory to the attacking client at a time.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wayland

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
wayland

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-27: 2Patch / Workaround · 2026-06-27: 2Technical Details · 2026-06-27: 206-27
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2023:2786: Wayland moderate security update for Rocky Linux 8. CVE-2021-3782 corrige overflow de referência no libwayland-server que permite use-after-free e vazamento de memória. Saiba mais: -> http://tinyurl.com/4rmxcjsb #RockyLinux https://t.co/3kMFyuWneD

    Post summary

    Rocky Linux has released a moderate security update (RLSA-2023:2786) to patch CVE-2021-3782, which addresses a reference overflow that causes use‑after‑free and memory leaks in libwayland-server.

    1001061
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2023:2786: Wayland moderate security update for Rocky Linux 8. CVE-2021-3782 corrige overflow de referência no libwayland-server que permite use-after-free e vazamento de memória. https://t.co/rJwKSnrX5i

    Post summary

    The tweet announces a Rocky Linux 8 security update that fixes CVE‑2021‑3782, a use‑after‑free bug in libwayland‑server.

    1000060
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwaylandwayland---

Explore more