CVE-2023-47118
ClickHouse: unauthenticated heap buffer overflow in the T64 codec
Technology
ClickHouse
CVSS Score
9.8 / 10.0
Affected Versions
ClickHouse before 23.3.16.7, 23.8 before 23.8.6.16, 23.9 before 23.9.4.11, 23.10 before 23.10.2.13
Upstream Fix
23.3.16.7, 23.8.6.16, 23.9.4.11, 23.10.2.13
Published
December 20, 2023
OSSeva Coverage
Fixed upstream
Description
A crafted payload sent to the native interface, port 9000/tcp by default, triggers a heap buffer overflow in the T64 codec's decompression and crashes the server process without authentication. Over HTTP the same bug needs valid credentials, because HTTP authentication happens first.
Is your ClickHouse deployment affected?
If you're running ClickHouse before 23.3.16.7, 23.8 before 23.8.6.16, 23.9 before 23.9.4.11, 23.10 before 23.10.2.13, you need this patch. Book a discovery call to get covered.