View at Official ubuntu advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2021-35331 negligible priority: Ubuntu including 1 source packages (tcl8.6), 12 status rows across 12 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, trusty, upstream, xenial): not-affected 6, ignored 4, DNE 1, needs-triage 1.
In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding