CVE-2021-37137

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
JFROGCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
nettynetty
𝑥
< 4.1.68
oraclebanking_apis
18.1 ≤
𝑥
≤ 18.3
oraclebanking_apis
19.1
oraclebanking_apis
19.2
oraclebanking_apis
20.1
oraclebanking_apis
21.1
oraclebanking_digital_experience
18.1
oraclebanking_digital_experience
18.2
oraclebanking_digital_experience
18.3
oraclebanking_digital_experience
19.1
oraclebanking_digital_experience
19.2
oraclebanking_digital_experience
20.1
oraclebanking_digital_experience
21.1
oraclecommerce_guided_search
11.3.2
oraclecommunications_brm_-_elastic_charging_engine
𝑥
< 12.0.0.4.6
oraclecommunications_brm_-_elastic_charging_engine
12.0.0.5.0
oraclecommunications_cloud_native_core_binding_support_function
1.10.0
oraclecommunications_diameter_signaling_router
8.0.0.0 ≤
𝑥
≤ 8.5.0.2
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
quarkusquarkus
𝑥
< 2.2.4
netapponcommand_insight
-
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netty
bullseye (security)
1:4.1.48-4+deb11u2
fixed
bullseye
1:4.1.48-4+deb11u2
fixed
stretch
no-dsa
bookworm
1:4.1.48-7+deb12u1
fixed
bookworm (security)
1:4.1.48-7+deb12u1
fixed
sid
1:4.1.48-10
fixed
trixie
1:4.1.48-10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netty
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
Fixed 1:4.1.48-5ubuntu0.1
released
jammy
Fixed 1:4.1.48-4+deb11u1build0.22.04.1
released
impish
ignored
hirsute
ignored
focal
Fixed 1:4.1.45-1ubuntu0.1~esm1
released
bionic
Fixed 1:4.1.7-4ubuntu0.1+esm2
released
xenial
Fixed 1:4.0.34-1ubuntu0.1~esm1
released
trusty
needs-triage
References