Описание
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
A flaw was found in Loki. A remote attacker can exploit this vulnerability by sending specially crafted queries with large limits, leading to excessive memory allocation. This can cause a Denial of Service (DoS) by impacting the availability of the Loki service.
Меры по смягчению последствий
To mitigate this issue, configure the Loki service to enforce stricter limits on query parameters. This can prevent excessive memory allocations caused by large queries. Refer to the Loki documentation for details on configuring query limits, such as maximum series or query length. A restart of the Loki service is required for any configuration changes to take effect, which may temporarily impact service availability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Hardened Images | loki3.6 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
Уязвимость компонента Query Engine системы для агрегации и хранения логов Loki, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3