OSV 1.4.0 · unreviewed · 修改于 2026-09-02 23:34
发布时间
2026-08-27 05:31
GitHub 审查时间
—
NVD 发布时间
2026-08-27 04:17
源文件
advisories/unreviewed/2026/08/GHSA-p6pc-q683-388g/GHSA-p6pc-q683-388g.json
stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP connections open, which, combined with the broker s use of edge-triggered epoll (EPOLLET) and MSG_PEEK in recv(), causes sockets to enter a permanent half-read state. When enough such connections accumulate, the broker stops receiving any further epoll events for those sockets and eventually hangs in epoll_wait, effectively refusing to process new messages.
该公告没有提供结构化的受影响软件包信息。