CVE-2021-24036
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.28% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-190
- Affected
- facebook/folly · facebook/hhvm
- Source
- cve-assign@fb.com
References
- https://github.com/facebook/folly/commit/4f304af1411e68851bdd00ef6140e9de4616f7d3Patch, Third Party Advisory
- https://hhvm.com/blog/2021/07/20/security-update.htmlProduct, Vendor Advisory
- https://www.facebook.com/security/advisories/cve-2021-24036Vendor Advisory
- https://github.com/facebook/folly/commit/4f304af1411e68851bdd00ef6140e9de4616f7d3Patch, Third Party Advisory
- https://hhvm.com/blog/2021/07/20/security-update.htmlProduct, Vendor Advisory
- https://www.facebook.com/security/advisories/cve-2021-24036Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.