CVE-2021-37137

EUVD-2021-2029
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
nettynetty
𝑥
< 4.1.68
oraclebanking_apis
18.1 ≤
𝑥
≤ 18.3
oraclebanking_apis
19.1
oraclebanking_apis
19.2
oraclebanking_apis
20.1
oraclebanking_apis
21.1
oraclebanking_digital_experience
18.1
oraclebanking_digital_experience
18.2
oraclebanking_digital_experience
18.3
oraclebanking_digital_experience
19.1
oraclebanking_digital_experience
19.2
oraclebanking_digital_experience
20.1
oraclebanking_digital_experience
21.1
oraclecommerce_guided_search
11.3.2
oraclecommunications_brm_-_elastic_charging_engine
𝑥
< 12.0.0.4.6
oraclecommunications_brm_-_elastic_charging_engine
12.0.0.5.0
oraclecommunications_cloud_native_core_binding_support_function
1.10.0
oraclecommunications_diameter_signaling_router
8.0.0.0 ≤
𝑥
≤ 8.5.0.2
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepeoplesoft_enterprise_peopletools
8.59
oraclewebcenter_portal
12.2.1.3.0
oraclewebcenter_portal
12.2.1.4.0
quarkusquarkus
𝑥
< 2.2.4
netapponcommand_insight
-
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netty
bookworm
1:4.1.48-7+deb12u1
fixed
bookworm (security)
1:4.1.48-7+deb12u1
fixed
bullseye
1:4.1.48-4+deb11u2
fixed
bullseye (security)
1:4.1.48-4+deb11u2
fixed
sid
1:4.1.48-10
fixed
stretch
no-dsa
trixie
1:4.1.48-10
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netty
bionic
Fixed 1:4.1.7-4ubuntu0.1+esm2
released
focal
Fixed 1:4.1.45-1ubuntu0.1~esm1
released
hirsute
ignored
impish
ignored
jammy
Fixed 1:4.1.48-4+deb11u1build0.22.04.1
released
kinetic
Fixed 1:4.1.48-5ubuntu0.1
released
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
needs-triage
xenial
Fixed 1:4.0.34-1ubuntu0.1~esm1
released
References