CVE-2020-8927

Severity
6.5MEDIUM
EPSS
0.3%
top 45.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateJun 3

Description

A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages128 packages

PyPIbrotli< 1.0.8
NVDgoogle/brotli< 1.0.8
crates.iocompu-brotli-sys0.0.0-01.0.9+1
Debianbrotli< 1.0.9-1+3
CVEListV5google_llc/brotlistable1.0.7

Also affects: Debian Linux 10.0, 9.0, Fedora 31, 32, 33, 34, 35, 36, Ubuntu Linux 16.04, 18.04, 20.04

🔴Vulnerability Details

8
OSV
IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library in github.com/google/brotli2025-06-03
GHSA
Integer overflow in the bundled Brotli C library2022-05-24
OSV
Integer overflow in the bundled Brotli C library2022-05-24
OSV
Integer overflow in the bundled Brotli C library2021-12-20
OSV
Integer overflow in the bundled Brotli C library2021-12-20

📋Vendor Advisories

4
Microsoft
Brotli Library Buffer Overflow Vulnerability2022-03-08
Ubuntu
Brotli vulnerability2020-10-05
Red Hat
brotli: buffer overflow when input chunk is larger than 2GiB2020-08-27
Debian
CVE-2020-8927: brotli - A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an ...2020

💬Community

5
Bugzilla
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [epel-7]2020-09-15
Bugzilla
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB2020-09-15
Bugzilla
CVE-2020-8927 golang-github-andybalholm-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]2020-09-15
Bugzilla
CVE-2020-8927 mingw-brotli: brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]2020-09-15
Bugzilla
CVE-2020-8927 brotli: buffer overflow when input chunk is larger than 2GiB [fedora-all]2020-09-15
CVE-2020-8927 (MEDIUM CVSS 6.5) | A buffer overflow exists in the Bro | cvebase.io