Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2023-47118

ClickHouse: unauthenticated heap buffer overflow in the T64 codec

Technology

ClickHouse

CVSS Score

9.8 / 10.0

Affected Versions

ClickHouse before 23.3.16.7, 23.8 before 23.8.6.16, 23.9 before 23.9.4.11, 23.10 before 23.10.2.13

Upstream Fix

23.3.16.7, 23.8.6.16, 23.9.4.11, 23.10.2.13

Published

December 20, 2023

OSSeva Coverage

Fixed upstream

Description

A crafted payload sent to the native interface, port 9000/tcp by default, triggers a heap buffer overflow in the T64 codec's decompression and crashes the server process without authentication. Over HTTP the same bug needs valid credentials, because HTTP authentication happens first.

Upstream record: NVD · CVE.org

Is your ClickHouse deployment affected?

If you're running ClickHouse before 23.3.16.7, 23.8 before 23.8.6.16, 23.9 before 23.9.4.11, 23.10 before 23.10.2.13, you need this patch. Book a discovery call to get covered.