CVE-2021-37137
—CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
- Vendors
- nettyoraclequarkusnetappdebian
- Products
- netty, banking apis, banking digital experience, commerce guided search, communications brm - elastic charging engine, communications cloud native core binding support function, communications diameter signaling router, peoplesoft enterprise peopletools, webcenter portal, quarkus, oncommand insight, debian linux
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.