{"id":"CVE-2021-3939","details":"Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.","modified":"2026-03-14T11:02:10.952331Z","published":"2021-11-17T04:15:06.977Z","references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/172848/Ubuntu-accountsservice-Double-Free-Memory-Corruption.html"},{"type":"WEB","url":"https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/1950149"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5149-1"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0.6.55-0ubuntu12\\~20.04"},{"fixed":"0.6.55-0ubuntu12\\~20.05"}]},{"events":[{"introduced":"0.6.55-0ubuntu13"},{"fixed":"0.6.55-0ubuntu13.3"}]},{"events":[{"introduced":"0.6.55-0ubuntu14"},{"fixed":"0.6.55-0ubuntu14.1"}]},{"events":[{"introduced":"0"},{"last_affected":"20.04"}]},{"events":[{"introduced":"0"},{"last_affected":"21.04"}]},{"events":[{"introduced":"0"},{"last_affected":"21.10"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3939.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}