Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.

Project Subscriptions

Vendors Products
Clickhouse Subscribe
Clickhouse Subscribe
Debian Linux Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3176-1 clickhouse security update
EUVD EUVD EUVD-2021-29358 Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of the source of the copy operation.
Ubuntu USN Ubuntu USN USN-6933-1 ClickHouse vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00153}

epss

{'score': 0.00163}


Wed, 25 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Clickhouse
Clickhouse clickhouse
CPEs cpe:2.3:a:yandex:clickhouse:*:*:*:*:*:*:*:* cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:*
Vendors & Products Yandex
Yandex clickhouse
Clickhouse
Clickhouse clickhouse

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2024-08-04T03:30:38.465Z

Reserved: 2021-10-14T00:00:00

Link: CVE-2021-42387

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-03-14T23:15:07.917

Modified: 2025-06-25T20:49:29.357

Link: CVE-2021-42387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses