// For flags

CVE-2021-37136

netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

La función Bzip2 decompression decoder no permite establecer restricciones de tamaño en los datos de salida descomprimidos (lo que afecta al tamaño de asignación usado durante la descompresión). Todos los usuarios de Bzip2Decoder están afectados. La entrada maliciosa puede desencadenar un OOME y así un ataque de DoS

A flaw was found in Netty's netty-codec due to size restrictions for decompressed data in the Bzip2Decoder. By sending a specially-crafted input, a remote attacker could cause a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-20 CVE Reserved
  • 2021-10-19 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-08-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
References (15)
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Netty
Search vendor "Netty"
Netty
Search vendor "Netty" for product "Netty"
< 4.1.68
Search vendor "Netty" for product "Netty" and version " < 4.1.68"
-
Affected
Quarkus
Search vendor "Quarkus"
Quarkus
Search vendor "Quarkus" for product "Quarkus"
< 2.2.4
Search vendor "Quarkus" for product "Quarkus" and version " < 2.2.4"
-
Affected
Oracle
Search vendor "Oracle"
Banking Apis
Search vendor "Oracle" for product "Banking Apis"
>= 18.1 <= 18.3
Search vendor "Oracle" for product "Banking Apis" and version " >= 18.1 <= 18.3"
-
Affected
Oracle
Search vendor "Oracle"
Banking Apis
Search vendor "Oracle" for product "Banking Apis"
19.1
Search vendor "Oracle" for product "Banking Apis" and version "19.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Apis
Search vendor "Oracle" for product "Banking Apis"
19.2
Search vendor "Oracle" for product "Banking Apis" and version "19.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Apis
Search vendor "Oracle" for product "Banking Apis"
20.1
Search vendor "Oracle" for product "Banking Apis" and version "20.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Apis
Search vendor "Oracle" for product "Banking Apis"
21.1
Search vendor "Oracle" for product "Banking Apis" and version "21.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
18.1
Search vendor "Oracle" for product "Banking Digital Experience" and version "18.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
18.2
Search vendor "Oracle" for product "Banking Digital Experience" and version "18.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
18.3
Search vendor "Oracle" for product "Banking Digital Experience" and version "18.3"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
19.1
Search vendor "Oracle" for product "Banking Digital Experience" and version "19.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
19.2
Search vendor "Oracle" for product "Banking Digital Experience" and version "19.2"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
20.1
Search vendor "Oracle" for product "Banking Digital Experience" and version "20.1"
-
Affected
Oracle
Search vendor "Oracle"
Banking Digital Experience
Search vendor "Oracle" for product "Banking Digital Experience"
21.1
Search vendor "Oracle" for product "Banking Digital Experience" and version "21.1"
-
Affected
Oracle
Search vendor "Oracle"
Coherence
Search vendor "Oracle" for product "Coherence"
12.2.1.4.0
Search vendor "Oracle" for product "Coherence" and version "12.2.1.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Coherence
Search vendor "Oracle" for product "Coherence"
14.1.1.0.0
Search vendor "Oracle" for product "Coherence" and version "14.1.1.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Commerce Guided Search
Search vendor "Oracle" for product "Commerce Guided Search"
11.3.2
Search vendor "Oracle" for product "Commerce Guided Search" and version "11.3.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Brm - Elastic Charging Engine
Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine"
< 12.0.0.4.6
Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine" and version " < 12.0.0.4.6"
-
Affected
Oracle
Search vendor "Oracle"
Communications Brm - Elastic Charging Engine
Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine"
12
Search vendor "Oracle" for product "Communications Brm - Elastic Charging Engine" and version "12"
0.0.5.0
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Binding Support Function
Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function"
1.10.0
Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function" and version "1.10.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Binding Support Function
Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function"
1.11.0
Search vendor "Oracle" for product "Communications Cloud Native Core Binding Support Function" and version "1.11.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Network Slice Selection Function
Search vendor "Oracle" for product "Communications Cloud Native Core Network Slice Selection Function"
1.8.0
Search vendor "Oracle" for product "Communications Cloud Native Core Network Slice Selection Function" and version "1.8.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Policy
Search vendor "Oracle" for product "Communications Cloud Native Core Policy"
1.15.0
Search vendor "Oracle" for product "Communications Cloud Native Core Policy" and version "1.15.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Security Edge Protection Proxy
Search vendor "Oracle" for product "Communications Cloud Native Core Security Edge Protection Proxy"
1.7.0
Search vendor "Oracle" for product "Communications Cloud Native Core Security Edge Protection Proxy" and version "1.7.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Cloud Native Core Unified Data Repository
Search vendor "Oracle" for product "Communications Cloud Native Core Unified Data Repository"
1.15.0
Search vendor "Oracle" for product "Communications Cloud Native Core Unified Data Repository" and version "1.15.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
>= 8.0.0.0 <= 8.5.0.2
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0.0 <= 8.5.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Instant Messaging Server
Search vendor "Oracle" for product "Communications Instant Messaging Server"
8.1
Search vendor "Oracle" for product "Communications Instant Messaging Server" and version "8.1"
-
Affected
Oracle
Search vendor "Oracle"
Helidon
Search vendor "Oracle" for product "Helidon"
1.4.10
Search vendor "Oracle" for product "Helidon" and version "1.4.10"
-
Affected
Oracle
Search vendor "Oracle"
Helidon
Search vendor "Oracle" for product "Helidon"
2.4.0
Search vendor "Oracle" for product "Helidon" and version "2.4.0"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.48
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.48"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.57
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.57"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.58
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.58"
-
Affected
Oracle
Search vendor "Oracle"
Peoplesoft Enterprise Peopletools
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools"
8.59
Search vendor "Oracle" for product "Peoplesoft Enterprise Peopletools" and version "8.59"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.3.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Webcenter Portal
Search vendor "Oracle" for product "Webcenter Portal"
12.2.1.4.0
Search vendor "Oracle" for product "Webcenter Portal" and version "12.2.1.4.0"
-
Affected
Netapp
Search vendor "Netapp"
Oncommand Insight
Search vendor "Netapp" for product "Oncommand Insight"
--
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
10.0
Search vendor "Debian" for product "Debian Linux" and version "10.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
11.0
Search vendor "Debian" for product "Debian Linux" and version "11.0"
-
Affected