Medium severity5.3NVD Advisory· Published Jun 3, 2024· Updated Jun 17, 2026
CVE-2024-36124
CVE-2024-36124
Description
iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class sun.misc.Unsafe to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.iq80.snappy:snappyMaven | < 0.5 | 0.5 |
Affected products
8- ghsa-coords7 versionspkg:maven/org.iq80.snappy/snappypkg:apk/wolfi/apache-nifi-toolkitpkg:apk/chainguard/apache-nifipkg:apk/chainguard/apache-nifi-compatpkg:apk/chainguard/apache-nifi-toolkitpkg:apk/wolfi/apache-nifipkg:apk/wolfi/apache-nifi-compat
< 0.5+ 6 more
- (no CPE)range: < 0.5
- (no CPE)range: < 2.0.0-r0
- (no CPE)range: < 2.0.0-r0
- (no CPE)range: < 2.0.0-r0
- (no CPE)range: < 2.0.0-r0
- (no CPE)range: < 2.0.0-r0
- (no CPE)range: < 2.0.0-r0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-8wh2-6qhj-h7j9ghsaADVISORY
- github.com/dain/snappy/security/advisories/GHSA-8wh2-6qhj-h7j9nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-36124ghsaADVISORY
News mentions
0No linked articles in our index yet.