← Vulnerability feed

Vulnerability record · CVE-2021-24025 · published 10 March 2021

CVE-2021-24025: Facebook hhvm heap-based buffer overflow vulnerability

Facebook · Hhvm

Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

9.8 CVSS 3.1 Critical EPSS 1.7% · top 24.3% CWE-122 · Heap-based buffer overflowCWE-190 · Integer overflow
9.8CVSS 3.1 base score, v2 7.5
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24025 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-36937Facebook hhvm broken cryptographic algorithm vulnerabilityHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous publish…EPSS 0.53%9.8CVE-2021-24036Facebook folly heap-based buffer overflow vulnerabilityPassing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possi…EPSS 3.3%9.8CVE-2020-1900Facebook hhvm use after free vulnerabilityWhen unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything …EPSS 1.4%9.8CVE-2020-1916Facebook hhvm heap-based buffer overflow vulnerabilityAn incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write…EPSS 1.4%9.8CVE-2020-1917Facebook hhvm heap-based buffer overflow vulnerabilityxbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its stan…EPSS 1.4%9.8CVE-2016-1000004Facebook hhvm insufficient verification of data authenticity vulnerabilityInsufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM v…EPSS 0.68%9.8CVE-2016-1000005Facebook hhvm type confusion vulnerabilitymcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed…EPSS 1.4%9.8CVE-2019-11930Facebook hhvm vulnerabilityAn invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM version…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2021-24025), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.