vulnerability
Red Hat JBoss EAP: CVE-2021-37137: Uncontrolled Resource Consumption
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:N/A:P) | Sep 9, 2021 | Sep 19, 2024 | Mar 25, 2026 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Sep 9, 2021
Added
Sep 19, 2024
Modified
Mar 25, 2026
Description
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.. A flaw was found in the Netty's netty-codec due to unrestricted chunk lengths in the SnappyFrameDecoder. By sending a specially-crafted input, a remote attacker could cause excessive memory usage resulting in a denial of service.
Solution
red-hat-jboss-eap-upgrade-latest
References
- CWE-400
- CVE-2021-37137
- https://attackerkb.com/topics/CVE-2021-37137
- https://access.redhat.com/security/cve/CVE-2021-37137
- https://bugzilla.redhat.com/show_bug.cgi?id=2004135
- https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv
- https://access.redhat.com/errata/RHSA-2022:4918
- https://access.redhat.com/errata/RHSA-2022:4919
- https://access.redhat.com/errata/RHSA-2022:4922
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-2029
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.