CVE-2021-37137

Severity
7.5HIGH
EPSS
2.4%
top 15.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 19
Latest updateOct 15

Description

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages13 packages

NVDnetty/netty< 4.1.68
NVDquarkus/quarkus< 2.2.4
Mavenio.netty:netty-codec4.0.04.1.68.Final
CVEListV5the_netty_project/nettyunspecified4.1.68Final

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

4
CVEList
CVE-2021-37137: The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage2021-10-19
OSV
CVE-2021-37137: The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage2021-10-19
OSV
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way2021-09-09
GHSA
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way2021-09-09

📋Vendor Advisories

7
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Snappy) — CVE-2021-371372024-10-15
Ubuntu
Netty vulnerabilities2023-04-28
Oracle
Oracle Oracle Communications Applications Risk Matrix: 5G gateway (Google Snappy) — CVE-2021-371372022-07-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Security Framework (Netty) — CVE-2021-371372022-04-15
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Netty) — CVE-2021-371372022-01-15