CVE-2021-37137 - CVE House
Back to Database
Status published High CVE-2021-37137

The Snappy frame decoder function doesn't restrict the chunk length...

Vulnerability Description

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-37137

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

The Netty project

View all reports →

Affected Software

Netty
Vulnerable Versions:
unspecified

Timeline

Official Publish: October 19th, 2021
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)