VDB
Sign up
HIGH7.5

GHSA-5xrh-qmmq-w6ch

Netty: SCTP reassembly nests buffers without bound

Quick fix

GHSA-5xrh-qmmq-w6ch — io.netty:netty-transport-sctp: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.2.15.Final</version> for io.netty:netty-transport-sctp

Details

For each non-complete SctpMessage fragment the handler does `fragments.put(streamId, Unpooled.wrappedBuffer(frag, byteBuf))`, wrapping the previous accumulator and the new slice into a *new* CompositeByteBuf every time. After N fragments the accumulator is an N-deep chain of composites, each holding references and component arrays; readableBytes()/getBytes() on the final buffer recurse N levels. There is no limit on N, on total bytes, or on the number of streamIdentifiers an attacker can open (each gets its own map entry). A peer that never sets the `complete` flag can grow this structure indefinitely from tiny 1-byte DATA chunks.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.netty:netty-transport-sctp
Introduced in: 4.2.0.FinalFixed in: 4.2.15.Final
Fix# pom.xml: bump <version>4.2.15.Final</version> for io.netty:netty-transport-sctp
Maven/io.netty:netty-transport-sctp
Introduced in: 0Fixed in: 4.1.135.Final
Fix# pom.xml: bump <version>4.1.135.Final</version> for io.netty:netty-transport-sctp

References