Skip to content
Apache HadoopGHSA-rmpj-7c96-mrg8

Apache Hadoop heap overflow before v2.10.2, v3.2.3, v3.3.2

Critical9.8CVE-2021-37404 · Published Jun 14, 2022 · updated Feb 22, 2024

There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.hadoop:hadoop-common
Maven
>= 3.3.0, < 3.3.23.3.2
>= 3.0.0, < 3.2.33.2.3
< 2.10.22.10.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-120, CWE-131, CWE-787
Also known as
CVE-2021-37404

More Apache Hadoop advisories

All Apache Hadoop
Advisory
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Medium6.2May 17, 2022
Improper Access Control in Apache Hadoop
High8.8May 17, 2022
Improper Authentication in Apache Hadoop
LowMay 17, 2022
Improper Authentication in Apache Hadoop
Medium6.5May 17, 2022
Apache Hadoop's LinuxContainerExecutor runs docker commands as root with insufficient input validation
High7.5May 17, 2022
Insecure Inherited Permissions in Apache Hadoop
High8.8May 14, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.