Vulnerability record · CVE-2021-33912 · published 19 January 2022
CVE-2021-33912: Libspf2 project libspf2 out-of-bounds write vulnerability
LLibspf2 Project · Libspf2
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.
Description
libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via an unauthenticated e-mail message from anywhere on the Internet) with a crafted SPF DNS record, because of incorrect sprintf usage in SPF_record_expand_data in spf_expand.c. The vulnerable code may be part of the supply chain of a site's e-mail infrastructure (e.g., with additional configuration, Exim can use libspf2; the Postfix web site links to unofficial patches for use of libspf2 with Postfix; older versions of spfquery relied on libspf2) but most often is not.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/shevek/libspf2/tree/8131fe140704eaae695e76b5cd09e39bd1dd220b | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/01/msg00015.html | Mailing ListThird Party Advisory |
| https://nathanielbennett.com/blog/libspf2-cve-jan-2022-disclosure | ExploitThird Party Advisory |
| https://security.gentoo.org/glsa/202401-22 | |
| https://github.com/shevek/libspf2/tree/8131fe140704eaae695e76b5cd09e39bd1dd220b | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/01/msg00015.html | Mailing ListThird Party Advisory |
| https://nathanielbennett.com/blog/libspf2-cve-jan-2022-disclosure | ExploitThird Party Advisory |
| https://security.gentoo.org/glsa/202401-22 |
Track CVE-2021-33912 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33912), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.