CVE-2021-36082
NixOS vulnerability analysis and mitigation

Overview

ntop nDPI 3.4 contains a stack-based buffer overflow vulnerability in the processClientServerHello function (OSS-Fuzz Report). The vulnerability was discovered and published on February 8, 2021, and was later fixed in a subsequent update (GitHub Commit).

Technical details

The vulnerability exists in the TLS protocol processing code, specifically in the processClientServerHello function within the TLS processing block. The issue manifests as a stack-based buffer overflow WRITE condition during the processing of TLS handshake messages (OSS-Fuzz Report). The vulnerability was introduced in commit 32bd3d7a and fixed in commit 1ec621c85b9411cc611652fd57a892cfef478af3.

Impact

The vulnerability has been classified as HIGH severity according to the ecosystem-specific assessment (OSS-Fuzz Vulns). Stack-based buffer overflows can potentially lead to system crashes, memory corruption, or arbitrary code execution.

Mitigation and workarounds

The vulnerability has been fixed in the nDPI codebase through additional checks and buffer size validations. The fix was implemented in commit 1ec621c85b9411cc611652fd57a892cfef478af3, which added further checks to prevent buffer overflow conditions (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-65622MEDIUM5.4
  • PHPPHP
  • snipe-it
NoYesDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management