CVE-2024-36124 is an out-of-bounds read vulnerability affecting the iq80 Snappy compression/decompression library, specifically impacting products like dain snappy. This flaw, rated Medium severity (CVSS 5.3), allows an unauthenticated attacker to trigger non-deterministic behavior or crash the JVM by providing specially crafted compressed data, due to Snappy's use of sun.misc.Unsafe bypassing standard bounds checks. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Users are advised to upgrade to iq80 Snappy version 0.5 as a quick fix.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5CPE matchmatch criteria | cpe:2.3:a:dain:snappy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.