CVE-2021-44962
Linux Debian vulnerability analysis and mitigation

Overview

An out-of-bounds read vulnerability exists in the GCode::extrude() functionality of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. The vulnerability was discovered in December 2021 and affects the 3D printing software Slic3r. A specially crafted STL file could lead to information disclosure when processed by the affected versions (CVE Details, Debian Tracker).

Technical details

The vulnerability occurs in the GCode::extrude() function when processing STL files with the --export-gcode argument. The function attempts to access the second to last element of paths.back().polyline.points on line 430 in GCode.cpp. While a polyline should contain more than 2 points by definition, certain input STL files can cause the std::vector length to be equal to or less than 2, leading to an out-of-bounds read on the heap (HackMD Report).

Impact

The vulnerability can cause an unexpected access on heap memory, potentially leading to information disclosure. When exploited, the vulnerability results in a heap-buffer-overflow condition that could expose sensitive information from memory (HackMD Report).

Mitigation and workarounds

As of the vulnerability disclosure, the affected versions include Slic3r libslic3r 1.3.0 and Master Commit b1a5500. The Debian security tracker indicates that the vulnerability remains unfixed in several distributions including bookworm, bullseye, and sid (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22857MEDIUM6.8
  • Linux DebianLinux Debian
  • freerdp-plugins
NoNoJan 14, 2026
CVE-2026-22856MEDIUM6.8
  • Linux DebianLinux Debian
  • freerdp2
NoNoJan 14, 2026
CVE-2026-22859MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 14, 2026
CVE-2026-22858MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 14, 2026
CVE-2026-22036LOW3.7
  • JavaScriptJavaScript
  • node-undici
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management