Resource exhaustion in Netty - CVE-2021-37136

 

Resource exhaustion in Netty - CVE-2021-37136

Published: May 12, 2022 / Updated: February 11, 2025


Vulnerability identifier: #VU63127
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37136
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in Bzip2 decompression decoder function. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

Netty
IBM Observability with Instana
Log Analysis
IBM Operations Analytics Predictive Insights
Netcool Operations Insight
IBM Cloud Transformation Advisor
OpenShift Logging
Red Hat Satellite
Autodesk Infraworks
Red Hat Integration - Service Registry
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling B2B Integrator
HPE Telco IP Mediation E-Media
Debian Linux
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Manager Server
Ubuntu
openEuler
B2B Advanced Communications
IBM Watson Machine Learning Accelerator
Security QRadar EDR
DataStage on Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
IBM Sterling Order Management
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JBoss Enterprise Application Platform
AMQ Streams
AMQ Broker
Fuse
Oracle Access Manager
libnetty-java (Ubuntu package)
netty-help
netty
netty (Debian package)
Voice Gateway
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
JBoss Data Grid
watsonx.data
IBM Security Guardium

How to mitigate CVE-2021-37136

Install updates from vendor's website.

Netty - update to 4.1.68
B2B Advanced Communications - update to 1.0.0.12
Log Analysis - update to 1.3.8
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
Netcool Operations Insight - update to 1.6.5
IBM Cloud Transformation Advisor - update to 3.2.1
Security QRadar EDR - update to 3.12.15
DataStage on Cloud Pak for Data - update to 4.8.5
OpenShift Logging - addressed in versions 5.2.10, 5.3.7, 5.4.1
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.0
JBoss Enterprise Application Platform - update to 7.4.5
Autodesk Infraworks - addressed in versions 2021.2 Hotfix 9, 2023.1 Hotfix 1
libnetty-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1:4.1.48-4+deb11u1build0.22.04.1, 1:4.1.48-5ubuntu0.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Cloud Pak for Security (CP4S) - update to 1.10.12.0
AMQ Streams - addressed in versions 2.0.0, 2.4.0, 2.5.0
watsonx.data - update to 2.0.2
Red Hat Integration - Service Registry - update to 2.3.0
IBM Cloud Pak for Watson AIOps - update to 3.7.1
netty-help - update to 4.1.13-12
netty - update to 4.1.13-12
netty - addressed in versions 4.1.44.Final-150200.3.4.2, 4.1.44.Final-150300.4.3.2, 4.1.44.Final-150400.3.3.2
netty (Debian package) - update to 1:4.1.48-4+deb11u1
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.8.0
IBM Sterling B2B Integrator - update to 6.1.2.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
AMQ Broker - update to 7.9.1
Fuse - update to 7.10.0
JBoss Data Grid - update to 8.3.0
HPE Telco IP Mediation E-Media - update to 8.5.1
IBM Sterling Order Management - update to 10.0.0.29
IBM Security Guardium - addressed in versions 11.0p360, 11.0p430

External References

Related Security Bulletins