cbcvebase.
CVE-2021-37137
published 2021-10-19

CVE-2021-37137: The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.28%
92.8th percentile
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiannetty< netty 1:4.1.48-6 (bookworm)netty 1:4.1.48-6 (bookworm)
nettynetty< 4.1.684.1.68
nettynetty>= 0 < 1:4.1.48-4+deb11u11:4.1.48-4+deb11u1
nettynetty>= 0 < 1:4.1.48-61:4.1.48-6
nettynetty>= 0 < 1:4.1.48-61:4.1.48-6
nettynetty>= 0 < 1:4.1.48-61:4.1.48-6
nettynetty>= 0 < 1:4.1.48-4+deb11u1build0.22.04.11:4.1.48-4+deb11u1build0.22.04.1
nettynetty>= 0 < 1:4.0.34-1ubuntu0.1~esm11:4.0.34-1ubuntu0.1~esm1
nettynetty>= 0 < 1:4.1.7-4ubuntu0.1+esm21:4.1.7-4ubuntu0.1+esm2
nettynetty>= 0 < 1:4.1.45-1ubuntu0.1~esm11:4.1.45-1ubuntu0.1~esm1
oraclebanking_apis
oraclebanking_apis
oraclebanking_apis
oraclebanking_apis
oraclebanking_apis18.1 – 18.3
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclebanking_digital_experience
oraclecommerce_guided_search

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.