OSV 1.4.0 · github-reviewed · 修改于 2026-08-19 00:32
发布时间
2026-08-19 00:32
GitHub 审查时间
2026-08-19 00:32
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-68mj-5wr7-6fgg/GHSA-68mj-5wr7-6fgg.json
ValueReader.readBytes() allocates a byte array sized by a wire-declared content length without validating it against actual frame data. A malicious AMQP peer triggers OOM by declaring a ~2GB string/bytes field.
src/main/java/com/rabbitmq/client/impl/ValueReader.java lines 83-95:
private static byte[] readBytes(final DataInputStream in) throws IOException {
final long contentLength = unsignedExtend(in.readInt());
if(contentLength < Integer.MAX_VALUE) {
final byte[] buffer = new byte[(int)contentLength]; // allocates before reading
in.readFully(buffer);
return buffer;
}
}
A malicious AMQP server sends a LongString field (type tag 'S') with declared length 0x7FFFFFFE (2,147,483,646). The check contentLength < Integer.MAX_VALUE passes. new byte[2147483646] attempts ~2GB allocation, causing OutOfMemoryError before readFully() attempts to read data.
The allocation size is attacker-controlled and is NOT validated against the frame size or TruncatedInputStream bounds. Exploitable pre-authentication via connection.start server-properties table.
Denial of service via JVM OutOfMemoryError. Crashes the entire JVM.
CWE-789: Memory Allocation with Excessive Size Value
Validate contentLength against the frame's remaining bytes or the negotiated max frame size (default 131,072) before allocating.