Heap-based buffer overflow in Hadoop - CVE-2021-37404

 

Heap-based buffer overflow in Hadoop - CVE-2021-37404

Published: October 26, 2022


Vulnerability identifier: #VU68739
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37404
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when opening a file path within the libhdfs native code. A remote attacker can pass specially crafted input to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Hadoop
DataStage on Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
IBM Qradar SIEM
openEuler
Netcool Operations Insight
hadoop-common-native
hadoop-httpfs
hadoop-client
hadoop-mapreduce-examples
hadoop-yarn
hadoop-hdfs
hadoop-tests
hadoop-common
hadoop-maven-plugin
hadoop-debuginfo
hadoop-debugsource
hadoop-devel
libhdfs
hadoop-yarn-security
hadoop
hadoop-mapreduce

How to mitigate CVE-2021-37404

Install updates from vendor's website.

Hadoop - addressed in versions 2.10.2, 3.2.3, 3.3.2
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Netcool Operations Insight - update to 1.6.7
hadoop-common-native - update to 3.3.4-1
hadoop-httpfs - update to 3.3.4-1
hadoop-client - update to 3.3.4-1
hadoop-mapreduce-examples - update to 3.3.4-1
hadoop-yarn - update to 3.3.4-1
hadoop-hdfs - update to 3.3.4-1
hadoop-tests - update to 3.3.4-1
hadoop-common - update to 3.3.4-1
hadoop-maven-plugin - update to 3.3.4-1
hadoop-debuginfo - update to 3.3.4-1
hadoop-debugsource - update to 3.3.4-1
hadoop-devel - update to 3.3.4-1
libhdfs - update to 3.3.4-1
hadoop-yarn-security - update to 3.3.4-1
hadoop - update to 3.3.4-1
hadoop-mapreduce - update to 3.3.4-1
IBM Cloud Pak for Watson AIOps - update to 3.6.0

External References

Related Security Bulletins