Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2021-37404

Apache Hadoop: heap buffer overflow in libhdfs

Technology

Apache Hadoop

CVSS Score

9.8 / 10.0

Affected Versions

2.9.0 to 2.10.1; 3.0.0 to 3.1.4; 3.2.0 to 3.2.2; 3.3.0 to 3.3.1

Upstream Fix

2.10.2; 3.2.3; 3.3.2

Published

June 13, 2022

OSSeva Coverage

Fixed upstream

Description

The libhdfs native library has a potential heap buffer overflow. Opening a file path supplied by a user without validation can cause denial of service or arbitrary code execution.

Upstream record: NVD · CVE.org

Is your Apache Hadoop deployment affected?

If you're running 2.9.0 to 2.10.1; 3.0.0 to 3.1.4; 3.2.0 to 3.2.2; 3.3.0 to 3.3.1, you need this patch. Book a discovery call to get covered.