Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade guava-libraries | Jul 30, 2024 | Apr 26, 2018 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Mar 14, 2019 | Apr 26, 2018 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 33172866 for version 12.1.3.0.0. | Jan 19, 2021 | Apr 26, 2018 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Apr 25, 2018 |
| Red_hat Jboss_eap | — | — | Nov 14, 2019 | Apr 26, 2018 |
| Redhat Openshift | — | Upgrade logging | Oct 8, 2019 | Apr 26, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 26, 2018 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.2.2Upgrade Splunk Enterprise to version 9.0.10Upgrade Splunk Enterprise to version 9.1.5 | Sep 30, 2025 | Apr 26, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub