CVE-2021-42391

Severity CVSS v4.0:
Pending analysis
Type:
CWE-369 Divide By Zero
Publication date:
14/03/2022
Last modified:
25/06/2025

Description

Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clickhouse:clickhouse:*:*:*:*:*:*:*:* 21.10.2.15 (excluding)