CVE-2020-8927
published 2025-05-30CVE-2020-8927: A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of…
PriorityP340medium6.5CVSS 3.1
AVNACLPRNUINSUCNILAL
EPSS
3.22%
86.8th percentile
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your IO::Compress::Brotli module to 0.007 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | brotli | < brotli 1.0.9-1 (bookworm) | brotli 1.0.9-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libio-compress-brotli-perl | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| brotli | < 1.0.8 | 1.0.8 | |
| google_llc | brotli | >= 0 < 1.0.9-1 | 1.0.9-1 |
| google_llc | brotli | >= 0 < 1.0.9-1 | 1.0.9-1 |
| google_llc | brotli | >= 0 < 1.0.9-1 | 1.0.9-1 |
| google_llc | brotli | >= 0 < 1.0.9-1 | 1.0.9-1 |
| google_llc | brotli | >= 0 < 1.0.8 | 1.0.8 |
| google_llc | brotli | stable – 1.0.7 | — |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 5.0.0 < 5.0.15 | 5.0.15 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 6.0.0 < 6.0.3 | 6.0.3 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 3.0.0 < 3.1.23 | 3.1.23 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 5.0.0 < 5.0.15 | 5.0.15 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_msrc6.5MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Brotli Library Buffer Overflow Vulnerability
vendor_msrc·2022-03-08·CVSS 6.5
CVE-2020-8927 [MEDIUM] Brotli Library Buffer Overflow Vulnerability
Brotli Library Buffer Overflow Vulnerability
FAQ: Why is this Google LLC CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in the Brotli library which is consumed by .NET and by Microsoft Visual Studio. It is being documented in the Security Update Guide to announce that the latest builds of .NET and Visual Studio are no longer vulnerable. Please see Security Update Guide Supports CVEs Assigned by Industry Partners for more information.
.NET and Visual Studio: .NET and Visual Studio
Google LLC: Google LLC
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Remediation: Release Notes
Ref
Ubuntu
Brotli vulnerability
vendor_ubuntu·2020-10-05
CVE-2020-8927 Brotli vulnerability
Title: Brotli vulnerability
Summary: Brotli could be made to crash if it received a specially crafted
input.
It was discovered that Brotli incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
brotli: buffer overflow when input chunk is larger than 2GiB
vendor_redhat·2020-08-27·CVSS 5.3
CVE-2020-8927 [MEDIUM] CWE-130 brotli: buffer overflow when input chunk is larger than 2GiB
brotli: buffer overflow when input chunk is larger than 2GiB
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
A buffer overflow flaw was found in the Brotli library where an attacker could control the input length of a "one-shot" decompression request to a script that can trigger a crash. This issue can happen when copying chunks of data larger than 2 GiB.
Mitigation: This flaw can be mitigated
Debian
CVE-2020-36846: libio-compress-brotli-perl - A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli ...
vendor_debian·2020·CVSS 9.8
CVE-2020-36846 [CRITICAL] CVE-2020-36846: libio-compress-brotli-perl - A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli ...
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your IO::Compress::Brotli module to 0.007 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2020-8927: brotli - A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an ...
vendor_debian·2020·CVSS 5.3
CVE-2020-8927 [MEDIUM] CVE-2020-8927: brotli - A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an ...
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
Scope: local
bookworm: resolved (fixed in 1.0.9-1)
bullseye: resolved (fixed in 1.0.9-1)
forky: resolved (fixed in 1.0.9-1)
sid: resolved (fixed in 1.0.9-1)
trixie: resolved (fixed in 1.0.9-1)
OSV
IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library in github.com/google/brotli
osv·2025-06-03
CVE-2020-36846 IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library in github.com/google/brotli
IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library in github.com/google/brotli
IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library in github.com/google/brotli
OSV
CVE-2020-36846: A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library
osv·2025-05-30·CVSS 9.8
CVE-2020-36846 [CRITICAL] CVE-2020-36846: A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your IO::Compress::Brotli module to 0.007 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
GHSA
GHSA-44qx-v2f9-7rq9: A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library
ghsa_unreviewed·2025-05-30·CVSS 5.3
CVE-2020-36846 [MEDIUM] GHSA-44qx-v2f9-7rq9: A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your IO::Compress::Brotli module to 0.007 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
GHSA
Integer overflow in the bundled Brotli C library
ghsa·2022-05-24
CVE-2020-8927 [MEDIUM] CWE-120 Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
OSV
Integer overflow in the bundled Brotli C library
osv·2022-05-24
CVE-2020-36846 [MEDIUM] Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
OSV
Integer overflow in the bundled Brotli C library
osv·2021-12-20
CVE-2020-36846 Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB.
An updated version of `brotli-sys` has not been released. If one cannot update the C library, its authors recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
In Rust the issue can be mitigated by migrating to the `brotli` crate, which provides a Rust implementation of Brotli compression and decompression that is not affected by this issue.
OSV
Integer overflow in the bundled Brotli C library
osv·2021-12-20
CVE-2020-36846 Integer overflow in the bundled Brotli C library
Integer overflow in the bundled Brotli C library
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB.
If one cannot update the C library, its authors recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
OSV
CVE-2020-36846: A buffer overflow exists in the Brotli library versions prior to 1
osv·2020-09-15
CVE-2020-36846 CVE-2020-36846: A buffer overflow exists in the Brotli library versions prior to 1
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
OSV
CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1
osv·2020-09-15·CVSS 6.5
CVE-2020-8927 [MEDIUM] CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [epel-7]
bugzilla·2020-09-15·CVSS 5.3
CVE-2020-8927 [MEDIUM] CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [epel-7]
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the
Bugzilla
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB
bugzilla·2020-09-15·CVSS 5.3
CVE-2020-8927 [MEDIUM] CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
Reference:
https://github.com/google/brotli/releases/tag/v1.0.9
Discussion:
Created brotli tracking bugs for this issue:
Affects: epel-7 [bug 1879230]
Affects: fedora-all [bug 1879226]
Created golang-github-andybalholm-brotli tracking bugs for this issue:
Affects: fedo
Bugzilla
CVE-2020-8927 golang-github-andybalholm-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
bugzilla·2020-09-15·CVSS 5.3
CVE-2020-8927 [MEDIUM] CVE-2020-8927 golang-github-andybalholm-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
CVE-2020-8927 golang-github-andybalholm-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: th
Bugzilla
CVE-2020-8927 mingw-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
bugzilla·2020-09-15·CVSS 5.3
CVE-2020-8927 [MEDIUM] CVE-2020-8927 mingw-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
CVE-2020-8927 mingw-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
bugzilla·2020-09-15·CVSS 5.3
CVE-2020-8927 [MEDIUM] CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
https://github.com/advisories/GHSA-5v8v-66v8-mwm7https://github.com/google/brotli/commit/223d80cfbec8fd346e32906c732c8ede21f0cea6https://github.com/google/brotli/pull/826https://github.com/timlegge/perl-IO-Compress-Brotli/blob/8b44c83b23bb4658179e1494af4b725a1bc476bc/Changes#L52https://nvd.nist.gov/vuln/detail/CVE-2020-8927
2025-05-30
Published