First published: Fri Jul 23 2021(Updated: )
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook Folly | <2021.07.22.00 | |
Facebook HHVM | <4.80.5 | |
Facebook HHVM | >=4.81.0<=4.102.1 | |
Facebook HHVM | >=4.103.0<=4.113.0 | |
Facebook HHVM | =4.114.0 | |
Facebook HHVM | =4.115.0 | |
Facebook HHVM | =4.116.0 | |
Facebook HHVM | =4.117.0 | |
Facebook HHVM | =4.118.0 | |
Facebook HHVM | =4.118.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24036.
The severity of CVE-2021-24036 is critical with a CVSS score of 9.8.
CVE-2021-24036 affects versions of Folly prior to v2021.07.22.00.
CVE-2021-24036 affects HHVM versions prior to 4.80.5 and versions between 4.81.0 and 4.102.1, 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0, and 4.118.1.
To fix the CVE-2021-24036 vulnerability, update to Folly v2021.07.22.00 or later for Facebook Folly, and update to HHVM 4.80.5 or later for Facebook HHVM.