Uploaded image for project: 'MariaDB Connector/C'
  1. MariaDB Connector/C
  2. CONC-835

Reject multipart (>16 MB) packets before authentication to prevent pre-auth OOM from a rogue server

    XMLWordPrintable

Details

    • Bug
    • Status: Closed (View Workflow)
    • Critical
    • Resolution: Fixed
    • None
    • 3.3.20, 3.4.10
    • Internal
    • None

    Description

      During the handshake/authentication phase, ma_net_read() reassembles multipart packets by reallocating the receive buffer for every 16 MB fragment, bounded only by max_allowed_packet (default 1 GB). A malicious or MitM'd server can stream endless max-length fragments and exhaust client memory before authentication completes.

      No legitimate pre-auth packet is anywhere near 16 MB, so the receive buffer should be capped to a small value (1 MB) during the handshake/auth phase and restored to the configured limit only after authentication succeeds. Oversized pre-auth packets must be rejected (CR_NET_PACKET_TOO_LARGE).

      Attachments

        Activity

          People

            georg Georg Richter
            diego dupin Diego Dupin
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.