First published: Mon Jun 13 2022(Updated: )
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Hadoop | >=2.9.0<2.10.2 | |
Apache Hadoop | >=3.0.0<=3.1.4 | |
Apache Hadoop | >=3.2.0<3.2.3 | |
Apache Hadoop | >=3.3.0<3.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37404 is a vulnerability in Apache Hadoop libhdfs native code that can result in a denial of service or arbitrary code execution.
CVE-2021-37404 can potentially lead to a heap buffer overflow in Apache Hadoop libhdfs native code when opening a file path provided by a user without validation.
CVE-2021-37404 has a severity rating of 9.8 (critical).
CVE-2021-37404 affects Apache Hadoop versions 2.9.0 to 2.10.2, 3.0.0 to 3.1.4, 3.2.0 to 3.2.3, and 3.3.0 to 3.3.2.
To fix CVE-2021-37404, users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.