Описание
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.
Отчет
This is an Important flaw in Netty's STOMP codec that allows a remote, unauthenticated attacker to cause a permanent memory leak. By sending an incomplete STOMP frame, an attacker can consume allocator memory that is never reclaimed, leading to a denial of service over time. This issue is particularly impactful as the memory leak persists even after the connection is closed, making it difficult to detect and prevent with standard connection-based rate limiting.
Меры по смягчению последствий
See https://github.com/netty/netty/security/advisories/GHSA-ghg5-c4jg-8q5j for fixed versions and remediation guidance.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 4 | netty-codec-stomp | Affected | ||
| Red Hat Fuse 7 | netty-codec-stomp | Affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk11-openshift-rhel8 | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk17-openshift-rhel8 | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 7 | jboss-eap-7/eap74-els-openjdk8-openshift-rhel8 | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 7 | netty-codec-stomp | Will not fix | ||
| Red Hat Single Sign-On 7 | netty-codec-stomp | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.
A flaw was found in Netty's StompSubframeDecoder component. A remote a ...
A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf (a buffer for bytes) that is never released, leading to a permanent memory leak. Over time, this uncontrolled memory consumption can result in a Denial of Service (DoS) for the application using the affected STOMP codec.
7.5 High
CVSS3