CVE-2021-24036: Integer Overflow
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-24036.
What is the severity of CVE-2021-24036?
The severity of CVE-2021-24036 is critical with a CVSS score of 9.8.
How does CVE-2021-24036 affect Facebook Folly?
CVE-2021-24036 affects versions of Folly prior to v2021.07.22.00.
How does CVE-2021-24036 affect Facebook HHVM?
CVE-2021-24036 affects HHVM versions prior to 4.80.5 and versions between 4.81.0 and 4.102.1, 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0, and 4.118.1.
How can I fix the CVE-2021-24036 vulnerability?
To fix the CVE-2021-24036 vulnerability, update to Folly v2021.07.22.00 or later for Facebook Folly, and update to HHVM 4.80.5 or later for Facebook HHVM.