Details
-
Bug
-
Status: Closed (View Workflow)
-
Critical
-
Resolution: Fixed
-
None
-
None
Description
During the handshake/authentication phase, ma_net_read() reassembles multipart packets by reallocating the receive buffer for every 16 MB fragment, bounded only by max_allowed_packet (default 1 GB). A malicious or MitM'd server can stream endless max-length fragments and exhaust client memory before authentication completes.
No legitimate pre-auth packet is anywhere near 16 MB, so the receive buffer should be capped to a small value (1 MB) during the handshake/auth phase and restored to the configured limit only after authentication succeeds. Oversized pre-auth packets must be rejected (CR_NET_PACKET_TOO_LARGE).