CVE-2021-44493
Linux Debian vulnerability analysis and mitigation

Overview

A buffer overflow vulnerability was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. The vulnerability was assigned CVE-2021-44493 and was disclosed in April 2022. The issue affects the $Extract functionality in both YottaDB and FIS GT.M database systems (NVD, CVE).

Technical details

The vulnerability occurs when crafted input causes a call to $Extract to force a signed integer holding the size of a buffer to take on a large negative number. This negative number is then used as the length of a memcpy call that occurs on the stack, resulting in a buffer overflow. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, and a CVSS v2.0 Base Score of 5.0 (MEDIUM) (NVD).

Impact

The vulnerability primarily affects system availability. According to the CVSS scoring, while there is no impact on confidentiality or integrity, the vulnerability can cause a high impact on system availability. This is reflected in the CVSS vector string which shows high availability impact (A:H) (NVD).

Mitigation and workarounds

The vulnerability has been fixed in versions after YottaDB r1.32 and FIS GT.M V7.0-000. Users should upgrade to newer versions to mitigate this vulnerability. For Debian systems, the fix is available in version 7.0-002-1 and later releases (Debian Tracker).

Community reactions

The vulnerability was discovered through fuzz testing of YottaDB, which was part of a broader security testing initiative that uncovered multiple vulnerabilities. This finding was one of 40 bugs fixed in the r1.34 release as part of this testing effort (GitLab Issue).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-33230HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33229HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33228HIGH7.3
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-33231MEDIUM6.7
  • Linux DebianLinux Debian
  • nvidia-cuda-toolkit
NoNoJan 20, 2026
CVE-2025-15281N/AN/A
  • WolfiWolfi
  • glibc-langpack-anp
NoYesJan 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management