Integer Overflow Leading to Out of Bounds Write in Folly and HHVM
CVE-2021-24036
9.8CRITICAL
What is CVE-2021-24036?
An integer overflow issue exists in Folly and HHVM, where an attacker can manipulate the size parameter when creating an IOBuf. This can lead to an out-of-bounds write in the heap, potentially allowing for remote code execution. Affected versions of Folly are those released before v2021.07.22.00, and specific versions of HHVM between 4.80.5 and 4.118.1. It is crucial for users to update to secure versions to mitigate the risk.
Affected Version(s)
folly < unspecified
HHVM 4.118.0
HHVM 4.117.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved