CVE-2021-37137
SnappyFrameDecoder doesn't restrict chunk length any may buffer skippable chunks in an unnecessary way
7.5
HIGH
CVSS 3.1
EPSS 2.4%
Description
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
How to fix CVE-2021-37137
To remediate CVE-2021-37137, upgrade the affected package to a fixed version below.
- —upgrade to 1:4.1.48-4+deb11u1 or later
- —no fix listed
- —upgrade to 4.1.68.Final or later
- —no fix listed
Is CVE-2021-37137 being exploited?
Low — EPSS is 2.4%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 1:4.1.48-4+deb11u1
- from 0
- >= 4.0.0, < 4.1.68.Final
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |