High severity7.5NVD Advisory· Published Oct 19, 2021· Updated Jun 17, 2026
CVE-2021-37137
CVE-2021-37137
Description
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.netty:netty-codecMaven | >= 4.0.0, < 4.1.68.Final | 4.1.68.Final |
org.jboss.netty:nettyMaven | >= 0 | — |
io.netty:nettyMaven | >= 0 | — |
Affected products
39- The Netty project/Nettyv5Range: unspecified
- ghsa-coords11 versionspkg:maven/io.netty/netty-codecpkg:maven/org.jboss.netty/nettypkg:maven/io.netty/nettypkg:apk/chainguard/druid-compatpkg:apk/wolfi/druid-compatpkg:rpm/opensuse/netty&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/netty&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/netty&distro=SUSE%20Manager%20Server%20Module%204.2pkg:rpm/suse/netty&distro=SUSE%20Manager%20Server%20Module%204.3pkg:rpm/suse/netty&distro=SUSE%20Manager%20Server%20Module%204.1pkg:apk/chainguard/hadoop-fips-3.3.6
>= 4.0.0, < 4.1.68.Final+ 10 more
- (no CPE)range: >= 4.0.0, < 4.1.68.Final
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 34.0.0-r6
- (no CPE)range: < 34.0.0-r6
- (no CPE)range: < 4.1.114-1.1
- (no CPE)range: < 4.1.75-150200.4.6.2
- (no CPE)range: < 4.1.44.Final-150300.4.3.2
- (no CPE)range: < 4.1.44.Final-150400.3.3.2
- (no CPE)range: < 4.1.44.Final-150200.3.4.2
- (no CPE)range: < 3.3.6-r0
cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*range: >=18.1,<=18.3
- cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*range: <12.0.0.4.6
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*Range: >=8.0.0.0,<=8.5.0.2
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
26- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-9vjp-v76f-g363ghsaADVISORY
- github.com/netty/netty/security/advisories/GHSA-9vjp-v76f-g363nvdThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2023/01/msg00008.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37137ghsaADVISORY
- security.netapp.com/advisory/ntap-20220210-0012/nvdThird Party Advisory
- www.debian.org/security/2023/dsa-5316nvdThird Party AdvisoryWEB
- github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/SnappyFrameDecoder.javaghsaWEB
- github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/SnappyFrameDecoder.javaghsaWEB
- github.com/netty/netty/blob/4.1/codec/src/main/java/io/netty/handler/codec/compression/SnappyFrameDecoder.javaghsaWEB
- github.com/netty/netty/commit/6da4956b31023ae967451e1d94ff51a746a9194fghsaWEB
- lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16@%3Ccommits.druid.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e@%3Cdev.tinkerpop.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20220210-0012ghsaWEB
- lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16%40%3Ccommits.druid.apache.org%3Envd
- lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e%40%3Cdev.tinkerpop.apache.org%3Envd
News mentions
0No linked articles in our index yet.