Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
iskorotkov/avro: CPU Exhaustion in Avro Decoder
Vulnerability Description
iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd64 / arm64 targets — so a producer can declare a block of up to math.MaxInt64 (~9.2 × 10¹⁸) elements followed by EOF (or any truncated payload), and the decoder will attempt that many no-op iterations before propagating the error. The realistic ceiling is "indefinite until the worker is killed externally" — a single hostile payload pins a CPU core until the process is OOM-killed, deadline-cancelled, or terminated. Remote, unauthenticated denial-of-service. This vulnerability is fixed in 2.33.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
Avro 资源管理错误漏洞
Vulnerability Description
Avro是hamba开源的一个快速 Go Avro 编解码器。 avro 2.33.0之前版本存在资源管理错误漏洞,该漏洞源于Avro数组和映射解码器循环处理攻击者控制的块计数而不检查底层读取器错误状态,可能导致远程未经验证的拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A