CVE-2021-37136

The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack

Published: 2021-10-19 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-37136 is rated Moderate Risk (58.3/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.19%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-37136

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-04 0.35% 1.19% +0.83%
2 2026-03-01 1.19% 0.35% -0.83%
3 2026-02-04 1.19%

Full EPSS history (34 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-37136

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 3.1 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 3.6 [email protected]
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2021-37136

GitHub Security Advisory for CVE-2021-37136

GHSA-grg4-wf29-r9vv · Severity: high · Ecosystem: maven — Bzip2Decoder doesn't allow setting size restrictions for decompressed data

OS Trackers for CVE-2021-37136

vendor priority summary link
debian not yet assigned CVE-2021-37136 not yet assigned priority: Debian including 1 source packages (netty), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2021-37136
redhat medium https://access.redhat.com/security/cve/CVE-2021-37136
suse high CVE-2021-37136 severity important: SUSE including 243 source package names (5.0.0-beta1.2.122:netty-4.1.75-150200.4.6.2, 5.1.0.6.40:netty-4.1.75-150200.4.6.2, …), 276 product×package rows across 42 product lines (Container suse/manager/5.0/x86_64/server, Container suse/multi-linux-manager/5.1/x86_64/server, … (42 product lines)): Known Affected 231, Fixed 31, Known Not Affected 14. https://www.suse.com/security/cve/CVE-2021-37136/
ubuntu medium CVE-2021-37136 medium priority: Ubuntu including 1 source packages (netty), 15 status rows across 15 suites (bionic, focal, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 10, ignored 5. https://ubuntu.com/security/CVE-2021-37136

Affected software / configurations for CVE-2021-37136

Vendor Product Version Raw CPE
netty netty < 4.1.68 cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
quarkus quarkus < 2.2.4 cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:*
oracle banking_apis >= 18.1, <= 18.3 cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:*
oracle banking_apis 19.1 cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*
oracle banking_apis 19.2 cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*
oracle banking_apis 20.1 cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*
oracle banking_apis 21.1 cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*
oracle banking_digital_experience 18.1 cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:*
oracle banking_digital_experience 18.2 cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:*
oracle banking_digital_experience 18.3 cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*
oracle banking_digital_experience 19.1 cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*
oracle banking_digital_experience 19.2 cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*
oracle banking_digital_experience 20.1 cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*
oracle banking_digital_experience 21.1 cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*
oracle coherence 12.2.1.4.0 cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*
oracle coherence 14.1.1.0.0 cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*
oracle commerce_guided_search 11.3.2 cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*
oracle communications_brm_-_elastic_charging_engine < 12.0.0.4.6 cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*
oracle communications_brm_-_elastic_charging_engine 12 cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12:0.0.5.0:*:*:*:*:*:*
oracle communications_cloud_native_core_binding_support_function 1.10.0 cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_binding_support_function 1.11.0 cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_network_slice_selection_function 1.8.0 cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_policy 1.15.0 cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_security_edge_protection_proxy 1.7.0 cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:*
oracle communications_cloud_native_core_unified_data_repository 1.15.0 cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*
oracle communications_diameter_signaling_router >= 8.0.0.0, <= 8.5.0.2 cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*
oracle communications_instant_messaging_server 8.1 cpe:2.3:a:oracle:communications_instant_messaging_server:8.1:*:*:*:*:*:*:*
oracle helidon 1.4.10 cpe:2.3:a:oracle:helidon:1.4.10:*:*:*:*:*:*:*
oracle helidon 2.4.0 cpe:2.3:a:oracle:helidon:2.4.0:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.48 cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.57 cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.58 cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.59 cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
oracle webcenter_portal 12.2.1.3.0 cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
oracle webcenter_portal 12.2.1.4.0 cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
netapp oncommand_insight cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
debian debian_linux 10.0 cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
debian debian_linux 11.0 cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

References for CVE-2021-37136

URL Tags
https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv Third Party Advisory
https://lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16%40%3Ccommits.druid.apache.org%3E
https://lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e%40%3Cdev.tinkerpop.apache.org%3E
https://lists.debian.org/debian-lts-announce/2023/01/msg00008.html Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20220210-0012/ Third Party Advisory
https://www.debian.org/security/2023/dsa-5316 Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Patch Third Party Advisory
cvelogic Threat Intelligence