CVE-2021-24036
9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.28% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-122 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-07-23 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| folly | |
| hhvm |
References
- https://github.com/facebook/folly/commit/4f304af1411e68851bdd00ef6140e9de4616f7d3
- https://hhvm.com/blog/2021/07/20/security-update.html
- https://www.facebook.com/security/advisories/cve-2021-24036
- https://github.com/facebook/folly/commit/4f304af1411e68851bdd00ef6140e9de4616f7d3
- https://hhvm.com/blog/2021/07/20/security-update.html
- https://www.facebook.com/security/advisories/cve-2021-24036
→ the Explorer · watch your stack · NVD