CVE Feed

    Dashboard / CVE / CVE-2021-42388

    CVE-2021-42388

    Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of the source of the copy operation.

    Published:Mar 14, 2022
    Last Modified:Jun 25, 2025
    EPS:Mar 14, 2022
    EPSS Score:0.00254
    CVSS Score:8.1

    Affected Products

    Vendor
    Clickhouse
    Product
    Clickhouse
    Vendor
    Debian
    Product
    Debian Linux

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High