InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocated memory, aka the "malformed PONG" issue.
[ { "signature_type": "Line", "id": "CVE-2021-33586-44bd76ff", "source": "https://github.com/inspircd/inspircd/commit/4350a11c663b0d75f8119743bffb7736d87abd4d", "signature_version": "v1", "target": { "file": "include/clientprotocolmsg.h" }, "digest": { "threshold": 0.9, "line_hashes": [ "172236433412257313883103957772383903383", "220703310501416717366140712732379042131", "52434925730221493171471376307921343860", "70281737129417841586534436710458404628", "263384407924776216272824341098924172406", "315415170026200256221787970084830905795" ] }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2021-33586-6c241bbe", "source": "https://github.com/inspircd/inspircd/commit/4350a11c663b0d75f8119743bffb7736d87abd4d", "signature_version": "v1", "target": { "file": "src/coremods/core_user/core_user.cpp" }, "digest": { "threshold": 0.9, "line_hashes": [ "324890397734487770979278848730261565209", "249933969203486859797144565555425798009", "122328167582706218575434760079144219617", "206397735007201542476051935054925026908" ] }, "deprecated": false } ]