Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-43618

26
FAUCET Score

CVE-2021-43618 describes an integer overflow and subsequent buffer overflow vulnerability in the GNU Multiple Precision Arithmetic Library (GMP) up to version 6.2.1, specifically within the mpz/inp_raw.c component. This flaw can lead to a denial-of-service condition (segmentation fault) on 32-bit platforms when processing crafted input, affecting products like Debian and NetApp. Rated with a CVSS score of 7.5 (High), it is a network-exploitable vulnerability with low attack complexity and no user interaction required, primarily impacting availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 6.2.1CPE matchmatch criteria
cpe:2.3:a:gmplib:gmp:*:*:*:*:*:*:x86:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.43%
Probability of exploitation in next 30 days
EPSS Percentile
87.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0343 is in the 78th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (44)

microsoftpatch availablevia msrc
Product: 18961-16820Fixed in: 6.1.2-6
microsoftpatch availablevia msrc
Product: 18962-16823Fixed in: 6.2.1-2
microsoftpatch availablevia msrc
Product: cm1 gmp 6.1.2-6 on CBL Mariner 1.0Fixed in: 6.1.2-6
microsoftpatch availablevia msrc
Product: cbl2 gmp 6.2.1-2 on CBL Mariner 2.0Fixed in: 6.2.1-2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: gmp-1:6.2.0-13.el9
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/cluster-logging-operator-bundle:v5.6.18-16
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/cluster-logging-rhel8-operator:v5.6.18-7
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-409
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/elasticsearch-operator-bundle:v5.6.18-16
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/elasticsearch-proxy-rhel8:v1.0.0-481
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/elasticsearch-rhel8-operator:v5.6.18-7
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/eventrouter-rhel8:v0.4.0-246
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/fluentd-rhel8:v1.14.6-216
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/kibana6-rhel8:v6.8.1-430
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/log-file-metric-exporter-rhel8:v1.1.0-226
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/logging-curator5-rhel8:v5.8.1-472
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/logging-loki-rhel8:v2.9.6-16
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/logging-view-plugin-rhel8:v5.6.18-3
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/loki-operator-bundle:v5.6.18-30
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/loki-rhel8-operator:v5.6.18-12
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/lokistack-gateway-rhel8:v0.1.0-528
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/opa-openshift-rhel8:v0.1.0-226
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/vector-rhel8:v0.21.0-127
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/cluster-logging-operator-bundle:v5.7.13-16
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/cluster-logging-rhel8-operator:v5.7.13-7
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/elasticsearch6-rhel8:v6.8.1-408
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/elasticsearch-operator-bundle:v5.7.13-19
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/elasticsearch-proxy-rhel8:v1.0.0-480
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/elasticsearch-rhel8-operator:v5.7.13-9
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/eventrouter-rhel8:v0.4.0-248
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/fluentd-rhel8:v1.14.6-215
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/kibana6-rhel8:v6.8.1-431
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/log-file-metric-exporter-rhel8:v1.1.0-228
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/logging-curator5-rhel8:v5.8.1-471
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/logging-loki-rhel8:v2.9.6-15
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/logging-view-plugin-rhel8:v5.7.13-3
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/loki-operator-bundle:v5.7.13-27
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/lokistack-gateway-rhel8:v0.1.0-527
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/opa-openshift-rhel8:v0.1.0-225
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/vector-rhel8:v0.28.1-57
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.7-RHEL-8Fixed in: openshift-logging/loki-rhel8-operator:v5.7.13-12
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gmp-1:6.1.2-11.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: gmp-1:6.1.2-11.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: gmp-1:6.1.2-11.el8_8.1
View patch

Vendor Advisories (2)

redhatCVE-2021-43618Moderate

gmp: Integer overflow and resultant buffer overflow via crafted input

Nov 15, 2021
microsoft2021-Nov/CVE-2021-43618Important

GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input leading to a segmentation fault on 32-bit platforms.

Nov 9, 2021

References

bugs.debian.org / 994405
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2022/Oct/8
Mailing ListThird Party Advisory
gmplib.org / list-archives/gmp-bugs/2021-September/005077.html
ExploitThird Party Advisory
gmplib.org / repo/gmp-6.2/rev/561a9c25298e
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2021/12/msg00001.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202309-13
security.netapp.com / advisory/ntap-20221111-0001
Third Party Advisory
openwall.com / lists/oss-security/2022/10/13/3
Mailing ListThird Party Advisory