Description
Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3176-1 | clickhouse security update |
EUVD |
EUVD-2021-29358 | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation. |
Ubuntu USN |
USN-6933-1 | ClickHouse vulnerabilities |
References
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 25 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clickhouse
Clickhouse clickhouse |
|
| CPEs | cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yandex
Yandex clickhouse |
Clickhouse
Clickhouse clickhouse |
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2024-08-04T03:30:38.465Z
Reserved: 2021-10-14T00:00:00.000Z
Link: CVE-2021-42387
No data.
Status : Modified
Published: 2022-03-14T23:15:07.917
Modified: 2025-06-25T20:49:29.357
Link: CVE-2021-42387
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN