Out-of-bounds read in snappy - CVE-2024-36124

 

Out-of-bounds read in snappy - CVE-2024-36124

Published: January 27, 2025


Vulnerability identifier: #VU103322
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-36124
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due Snappy tries to read outside the bounds of the given byte arrays when uncompressing certain data. A remote attacker can create a non-deterministic behavior or crash the JVM.


Affected software

snappy
Storage Copy Data Management
watsonx.data
IBM Spectrum Protect Plus
IBM Cloud Pak for Business Automation
IBM Sterling B2B Integrator
IBM Cloud Application Performance Management (APM)
IBM Automation Decision Services
Siebel CRM Integration
Dell Data Lakehouse

How to mitigate CVE-2024-36124

Install updates from vendor's website.

snappy - update to 0.5
watsonx.data - update to 2.1.1
IBM Spectrum Protect Plus - update to 10.1.17.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF007, 24.0.1-IF006, 25.0.0-IF003
Dell Data Lakehouse - update to 1.4.0.0
Storage Copy Data Management - update to 2.2.25.0
IBM Sterling B2B Integrator - addressed in versions 6.1.2.6, 6.2.0.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
IBM Automation Decision Services - addressed in versions 23.0.1.0.6, 24.0.0.0.8, 25.0.0.0.3

External References

Related Security Bulletins