Description
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6150 | There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher. |
Github GHSA |
GHSA-rmpj-7c96-mrg8 | Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2 |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T01:16:03.989Z
Reserved: 2021-07-23T00:00:00.000Z
Link: CVE-2021-37404
No data.
Status : Modified
Published: 2022-06-13T07:15:08.327
Modified: 2024-11-21T06:15:05.910
Link: CVE-2021-37404
OpenCVE Enrichment
No data.
EUVD
Github GHSA