High severity7.5NVD Advisory· Published Oct 19, 2021· Updated Jun 17, 2026
CVE-2021-37136
CVE-2021-37136
Description
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.netty:netty-codecMaven | < 4.1.68.Final | 4.1.68.Final |
org.jboss.netty:nettyMaven | >= 0 | — |
io.netty:nettyMaven | >= 0 | — |
Affected products
50- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*range: >=18.1,<=18.3
- cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*range: <12.0.0.4.6
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12:0.0.5.0:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*Range: >=8.0.0.0,<=8.5.0.2
- cpe:2.3:a:oracle:communications_instant_messaging_server:8.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:helidon:1.4.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:helidon:1.4.10:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:helidon:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
- osv-coords11 versionspkg:apk/chainguard/druid-compatpkg:apk/chainguard/hadoop-fips-3.3.6pkg:apk/wolfi/druid-compatpkg:maven/io.netty/nettypkg:maven/io.netty/netty-codecpkg:maven/org.jboss.netty/nettypkg:rpm/opensuse/netty&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/netty&distro=openSUSE%20Tumbleweedpkg:rpm/suse/netty&distro=SUSE%20Manager%20Server%20Module%204.1pkg:rpm/suse/netty&distro=SUSE%20Manager%20Server%20Module%204.2pkg:rpm/suse/netty&distro=SUSE%20Manager%20Server%20Module%204.3
< 34.0.0-r6+ 10 more
- (no CPE)range: < 34.0.0-r6
- (no CPE)range: < 3.3.6-r0
- (no CPE)range: < 34.0.0-r6
- (no CPE)range: >= 0
- (no CPE)range: < 4.1.68.Final
- (no CPE)range: >= 0
- (no CPE)range: < 4.1.75-150200.4.6.2
- (no CPE)range: < 4.1.114-1.1
- (no CPE)range: < 4.1.44.Final-150200.3.4.2
- (no CPE)range: < 4.1.44.Final-150300.4.3.2
- (no CPE)range: < 4.1.44.Final-150400.3.3.2
- The Netty project/Nettyv5Range: unspecified
Patches
Vulnerability mechanics
References
26- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-grg4-wf29-r9vvghsaADVISORY
- github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vvnvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2023/01/msg00008.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37136ghsaADVISORY
- security.netapp.com/advisory/ntap-20220210-0012/nvdThird Party Advisory
- www.debian.org/security/2023/dsa-5316nvdThird Party AdvisoryWEB
- github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/Bzip2Decoder.javaghsaWEB
- github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/Bzip2Decoder.javaghsaWEB
- github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/Bzip2Decoder.javaghsaWEB
- github.com/netty/netty/commit/41d3d61a61608f2223bb364955ab2045dd5e4020ghsaWEB
- lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e@%3Cdev.tinkerpop.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20220210-0012ghsaWEB
- lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e%40%3Cdev.tinkerpop.apache.org%3Envd
News mentions
0No linked articles in our index yet.