VDB
Sign up
MEDIUM6.2

GHSA-q6v9-43v5-jv9q

CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution

Quick fix

GHSA-q6v9-43v5-jv9q — CoreWCF.UnixDomainSocket: upgrade to the fixed version with the command below.

dotnet add package CoreWCF.UnixDomainSocket --version 1.8.1

Details

### Impact Race condition in POSIX peer identity resolution may attribute one connection’s identity to another (getpwuid/getgrgid non-reentrant) and may crash the host process under contention.

### Patches Fixed in CoreWCF v1.8.1 and v1.9.1

### Workarounds Restrict UDS filesystem permissions so that only trusted local users can connect to the socket path. The race still exists but the attacker pool is constrained.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/CoreWCF.UnixDomainSocket
Introduced in: 0Fixed in: 1.8.1
Fixdotnet add package CoreWCF.UnixDomainSocket --version 1.8.1
NuGet/CoreWCF.UnixDomainSocket
Introduced in: 1.9.0Fixed in: 1.9.1
Fixdotnet add package CoreWCF.UnixDomainSocket --version 1.9.1

References