CVE-2021-37404
published 2022-06-13CVE-2021-37404: There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.89%
85.4th percentile
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | hadoop | — | — |
| apache | hadoop | >= 2.9.0 < 2.10.2 | 2.10.2 |
| apache | hadoop | 3.0.0 – 3.1.4 | — |
| apache | hadoop | >= 3.2.0 < 3.2.3 | 3.2.3 |
| apache | hadoop | >= 3.3.0 < 3.3.2 | 3.3.2 |
| apache_software_foundation | apache_hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
| apache_software_foundation | apache_hadoop | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_apache9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hadoop-hdfs: Heap buffer overflow in Apache Hadoop libhdfs
vendor_redhat·2022-06-13·CVSS 9.8
CVE-2021-37404 [CRITICAL] CWE-131 hadoop-hdfs: Heap buffer overflow in Apache Hadoop libhdfs
hadoop-hdfs: Heap buffer overflow in Apache Hadoop libhdfs
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
A flaw was found in Apache Hadoop. Opening a file path provided by a user without validation may result in a denial of service or arbitrary code execution.
Statement: This package is a transitive dependency and is not used directly in the Red Hat products. Hence, it is categorized as a Moderate impact.
Package: hadoop-hdfs (Red Hat Fuse 7) - Not affected
Package: hadoop-hdfs (Red Hat JBoss Fuse 6) - Out of support scope
Package: openshift4/ose-metering-hadoop (R
Apache
Apache hadoop: CVE-2021-37404
vendor_apache·CVSS 9.8
CVE-2021-37404 [CRITICAL] Apache hadoop: CVE-2021-37404
Apache hadoop: CVE-2021-37404
There is a potential heap buffer overflow in libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution.
GHSA
Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
ghsa·2022-06-14
CVE-2021-37404 [CRITICAL] CWE-120 Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
OSV
Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
osv·2022-06-14
CVE-2021-37404 [CRITICAL] Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-06-13
Published