There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://lists.apache.org/thread/2h56ztcj3ojc66qzf1nno88vjw9vd4wo | mailing list |
https://security.netapp.com/advisory/ntap-20220715-0007/ | third party advisory |