CVE-2021-37137
Severity
7.5HIGH
EPSS
2.4%
top 15.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 19
Latest updateOct 15
Description
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages13 packages
Also affects: Debian Linux 10.0, 11.0
Patches
🔴Vulnerability Details
4CVEList▶
CVE-2021-37137: The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage↗2021-10-19
OSV▶
CVE-2021-37137: The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage↗2021-10-19
OSV▶
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way↗2021-09-09
GHSA▶
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way↗2021-09-09
📋Vendor Advisories
7Oracle
▶
Oracle▶
Oracle Oracle Communications Applications Risk Matrix: 5G gateway (Google Snappy) — CVE-2021-37137↗2022-07-15
Oracle
▶
Oracle
▶