Heap-based buffer overflow in Hadoop - CVE-2021-37404
Published: October 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when opening a file path within the libhdfs native code. A remote attacker can pass specially crafted input to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
DataStage on Cloud Pak for Data
IBM Cloud Pak for Watson AIOps
IBM Qradar SIEM
openEuler
Netcool Operations Insight
hadoop-common-native
hadoop-httpfs
hadoop-client
hadoop-mapreduce-examples
hadoop-yarn
hadoop-hdfs
hadoop-tests
hadoop-common
hadoop-maven-plugin
hadoop-debuginfo
hadoop-debugsource
hadoop-devel
libhdfs
hadoop-yarn-security
hadoop
hadoop-mapreduce
How to mitigate CVE-2021-37404
DataStage on Cloud Pak for Data - update to 4.8.5
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Pack 3
Netcool Operations Insight - update to 1.6.7
hadoop-common-native - update to 3.3.4-1
hadoop-httpfs - update to 3.3.4-1
hadoop-client - update to 3.3.4-1
hadoop-mapreduce-examples - update to 3.3.4-1
hadoop-yarn - update to 3.3.4-1
hadoop-hdfs - update to 3.3.4-1
hadoop-tests - update to 3.3.4-1
hadoop-common - update to 3.3.4-1
hadoop-maven-plugin - update to 3.3.4-1
hadoop-debuginfo - update to 3.3.4-1
hadoop-debugsource - update to 3.3.4-1
hadoop-devel - update to 3.3.4-1
libhdfs - update to 3.3.4-1
hadoop-yarn-security - update to 3.3.4-1
hadoop - update to 3.3.4-1
hadoop-mapreduce - update to 3.3.4-1
IBM Cloud Pak for Watson AIOps - update to 3.6.0