Critical severity9.8NVD Advisory· Published Jul 23, 2021· Updated Jun 17, 2026
CVE-2021-24036
CVE-2021-24036
Description
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*range: <4.80.5
- cpe:2.3:a:facebook:hhvm:4.114.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.115.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.116.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.117.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.118.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.118.1:*:*:*:*:*:*:*
- (no CPE)range: 4.118.0
Patches
Vulnerability mechanics
References
3- github.com/facebook/folly/commit/4f304af1411e68851bdd00ef6140e9de4616f7d3nvdPatchThird Party Advisory
- hhvm.com/blog/2021/07/20/security-update.htmlnvdProductVendor Advisory
- www.facebook.com/security/advisories/cve-2021-24036nvdVendor Advisory
News mentions
0No linked articles in our index yet.