LiveActive security incident?Get immediate response
CVE Record

CVE-2021-38383: OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.

OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

OwnTone versions through 28.1 contain a memory-safety flaw in network binding logic. The public record does not state business impact, severity, or confirmed exploitation. Treat this as a software hygiene issue that becomes more important where OwnTone is exposed broadly or runs on shared infrastructure.

Executive priority

Medium operational priority where OwnTone is deployed, higher if internet-facing or mission-critical. The available evidence does not justify emergency treatment without confirmed exposure, exploit activity, or a severity score.

Technical view

CVE-2021-38383 is a use-after-free in net_bind() in misc.c in OwnTone, also known as owntone-server, through version 28.1. The source bundle provides no CVSS score, CWE mapping, exploit evidence, or detailed attack preconditions. A referenced GitHub commit appears to address the affected code.

Likely exposure

Exposure is limited to environments running OwnTone or owntone-server through 28.1. The sources do not prove remote reachability, default exposure, or which configurations trigger the vulnerable path, so asset validation is required.

Exploitation context

The bundle says this CVE is not in KEV and provides no cited evidence of active exploitation. Because the issue is a use-after-free, potential outcomes may include crashes or memory corruption, but the public sources here do not establish exploitability or impact.

Researcher notes

The record is sparse: affected range is stated as through 28.1, but no CVSS, CWE, attack vector, or exploit status is provided. Avoid assuming remote code execution. Review the linked commit and release history to determine fixed builds and code-path reachability.

Mitigation direction

  • Inventory OwnTone or owntone-server installations and record versions.
  • Prioritize systems running OwnTone through 28.1.
  • Review vendor guidance and releases containing commit 246d8ae0.
  • Upgrade to a version confirmed to include the fix.
  • Restrict network exposure until remediation is verified.

Validation and detection

  • Check package, container, or source version for OwnTone deployments.
  • Confirm whether deployed code includes commit 246d8ae0.
  • Review service exposure and firewall rules for OwnTone hosts.
  • Check logs for abnormal restarts or crashes around network binding.
  • Document any compensating controls if upgrade is delayed.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-38383 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.