CVE-2021-24028: An invalid free in Thrift's table-based serialization can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2021.02.22.00.

Overview

Severity
Critical (CVSS 9.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit Status
Not Exploited
Patch Tuesday
2026-Aug
Released
2026-08-07
EPSS Score
1.75% (percentile: 75.6%)

Affected Products (1)

Mariner

  • azl3 thrift 0.15.0-5 on Azure Linux 3.0

Revision History

  • 2026-08-07: Information published.