Bugzilla – Bug 1197132
VUL-0: CVE-2020-36518: jackson-databind: StackOverflow exception via a large depth of nested objects
Last modified: 2024-05-30 18:56:29 UTC
CVE-2020-36518 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-36518 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36518 https://github.com/FasterXML/jackson-databind/issues/2816 http://www.cvedetails.com/cve/CVE-2020-36518/
It looks like this issue has been fixed upstream in v2.13.0, probably with those two commits [0][1]. The commit history is not very clear, it's possible that others commits around those ones are also fixing the issue. I currently don't know if v2.10.5 that we ship in SUSE:SLE-15-SP2:Update is affected or not. [0] https://github.com/FasterXML/jackson-databind/commit/51fd2faab70c9c8eb7ae43c200f8480f24ba74d8 [1] https://github.com/FasterXML/jackson-databind/commit/15c21aaa2327ddd9faf0cbb010bc8142d9e4008f
SUSE-SU-2022:1678-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1177616,1182481,1197132 CVE References: CVE-2020-25649,CVE-2020-28491,CVE-2020-36518 JIRA References: Sources used: openSUSE Leap 15.4 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-bom-2.13.0-150200.3.3.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 openSUSE Leap 15.3 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-bom-2.13.0-150200.3.3.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Manager Server 4.1 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Manager Retail Branch Server 4.1 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Manager Proxy 4.1 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise Server for SAP 15-SP2 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise Server 15-SP2-LTSS (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise Server 15-SP2-BCL (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise Realtime Extension 15-SP2 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise Module for SUSE Manager Server 4.3 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 SUSE Enterprise Storage 7 (src): jackson-annotations-2.13.0-150200.3.6.1, jackson-core-2.13.0-150200.3.6.1, jackson-databind-2.13.0-150200.3.9.1, jackson-dataformats-binary-2.13.0-150200.3.3.3 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Done, closing.