Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-42388

ClickHouse: heap out-of-bounds read in the LZ4 codec (lower bound)

Technology

ClickHouse

CVSS Score

8.1 / 10.0

Affected Versions

ClickHouse before 21.10.2.15

Upstream Fix

21.10.2.15

Published

March 14, 2022

OSSeva Coverage

Fixed upstream

Description

The LZ4 decompression loop reads a 16-bit offset from the compressed data and uses it in a copy without checking the lower bound of the source, so a malicious query causes a heap out-of-bounds read. Reported by the JFrog Security Research team.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse before 21.10.2.15, you need this patch. Book a discovery call to get covered.