Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-43304

ClickHouse: heap buffer overflow in the LZ4 codec

Technology

ClickHouse

CVSS Score

8.8 / 10.0

Affected Versions

ClickHouse before 21.10.2.15

Upstream Fix

21.10.2.15

Published

March 14, 2022

OSSeva Coverage

Fixed upstream

Description

When parsing a malicious query, the LZ4 decompression loop does not check that a copy operation stays within the destination buffer, causing a heap buffer overflow. Reported by the JFrog Security Research team.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse before 21.10.2.15, you need this patch. Book a discovery call to get covered.