{"id":"CVE-2021-44538","details":"The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.","modified":"2026-08-19T11:48:26.776829635Z","published":"2021-12-14T14:15:09.410Z","related":["SUSE-SU-2022:0058-1","openSUSE-SU-2022:0058-1","openSUSE-SU-2024:11698-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"},{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://gitlab.matrix.org/matrix-org/olm/-/tags"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/01/msg00001.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5034"},{"type":"FIX","url":"https://matrix.org/blog/2021/12/13/disclosure-buffer-overflow-in-libolm-and-matrix-js-sdk"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cinnyapp/cinny","events":[{"introduced":"0"},{"fixed":"5d380453a4a85728d89b28428600cdc7bfc451e4"}],"database_specific":{"cpe":"cpe:2.3:a:cinny_project:cinny:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.6.0"}],"source":"CPE_RANGE"}}],"versions":["v1.5.1","v1.5.0","v1.2.0","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44538.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/element-hq/element-desktop","events":[{"introduced":"0"},{"fixed":"6e28c141abfb688d8d5ec8dca8a5033098f6da76"}],"database_specific":{"source":"CPE_RANGE","cpe":["cpe:2.3:a:matrix:element:*:*:*:*:desktop:*:*:*","cpe:2.3:a:matrix:element:*:*:*:*:web:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"1.9.7"}]}}],"versions":["v1.9.6","v1.9.5","v1.9.4","v1.9.1","v1.9.0","v1.8.5","v1.8.0","v1.7.34","v1.7.33","v1.7.32","v1.7.31","v1.7.31-rc.1","v1.7.29","v1.7.29-rc.1","v1.7.23","v1.7.23-rc.1","v1.7.22","v1.7.22-rc.1","v1.7.20","v1.7.19","v1.7.19-rc.1","v1.7.14","v1.7.14-rc.1","v1.7.13","v1.7.13-rc.1","v1.7.12","v1.7.11","v1.7.11-rc.1","v1.7.5","v1.7.5-rc.1","v1.7.2","v1.7.1","v1.7.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44538.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/element-hq/element-web","events":[{"introduced":"0"},{"fixed":"eae38311b24da6801366780fe889aafe2d892e9f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.9.7"}],"source":"CPE_RANGE","cpe":["cpe:2.3:a:matrix:element:*:*:*:*:desktop:*:*:*","cpe:2.3:a:matrix:element:*:*:*:*:web:*:*:*"]}}],"versions":["v1.9.6","v1.9.6-rc.2","v1.9.5","v1.9.5-rc.1","v1.7.30","v1.7.30-rc.1","v1.7.23","v1.7.23-rc.1","v1.7.16","v1.7.16-rc.1","v1.7.14","v1.7.14-rc.1","v1.7.13","v1.7.13-rc.1","v1.7.11","v1.7.11-rc.1","v1.7.9","v1.7.9-rc.1","v1.7.2","v1.7.1","v1.7.0","v1.5.10","v1.5.3","v1.4.2","v1.4.2-rc.1","v1.4.1","v1.4.0","v1.4.0-rc.2","v1.4.0-rc.1","v0.17.8","v0.17.8-rc.1","v0.16.3","v0.16.3-rc.2","v0.16.3-rc.1","v0.16.0","v0.16.0-rc.2","v0.16.0-rc.1","v0.15.5","v0.15.5-rc.1","v0.15.4","v0.15.4-rc.1","v0.15.1","v0.15.0","v0.15.0-rc.6","v0.15.0-rc.5","v0.15.0-rc.4","v0.15.0-rc.3","v0.15.0-rc.2","v0.15.0-rc.1","v0.14.3-rc.1","v0.12.2","v0.12.1","v0.12.1-rc.1","v0.12.0-rc.1","v0.10.0","v0.10.0-rc.2","v0.9.3","v0.9.2","v0.8.3","v0.8.2","v0.8.1","v0.8.0","v0.7.5-r1","v0.7.5","v0.7.4-r1","v0.7.4","v0.7.3","v0.7.2","v0.7.1","v0.7.0","v0.6.1","v0.6.0","v0.5.0","v0.4.1","v0.4.0","v0.3.0","v0.1.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44538.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/matrix-org/matrix-js-sdk","events":[{"introduced":"c874783742f17921830aa274106d65e3e8af903c"},{"fixed":"f4839a3b4f1877111b2e0360a1b3b0dd2047193e"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:matrix:javascript_sdk:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.4.2"},{"fixed":"15.2.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44538.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/schildichat/schildichat-desktop","events":[{"introduced":"0"},{"fixed":"5aaedf0f19ba337fcc837955eb6171f7c6ebc311"}],"database_specific":{"cpe":["cpe:2.3:a:schildi:schildichat:*:*:*:*:desktop:*:*:*","cpe:2.3:a:schildi:schildichat:*:*:*:*:web:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"1.9.7-sc1"}],"source":"CPE_RANGE"}}],"versions":["v1.9.5-sc.2","v1.9.0-sc.1","v1.8.5-sc1","v1.8.4-sc1","v1.7.32-sc1","v1.7.29-sc1","v1.7.24-sc1","v1.7.22-sc1","v1.7.20-sc1","v1.7.17-sc1","v1.7.16","v1.7.15","v1.7.14","v1.7.13","v1.7.12","v1.7.8"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44538.json"}},{"ranges":[{"type":"GIT","repo":"https://gitlab.matrix.org/matrix-org/olm","events":[{"introduced":"6753595300767dd70150831dbbe6f92d64e75038"},{"fixed":"797183f27f1c8cdb9d4551aaa317bd13ff02401b"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:matrix:olm:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.1.4"},{"fixed":"3.2.8"}]}}],"versions":["3.2.7","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.5","3.1.4"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-44538.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}