PT-2026-102744 · Bitnami · Rabbitmq-C

Publicado

2026-09-29

·

Atualizado

2026-09-29

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size t underflow in amqp handle input() in librabbitmq/amqp connection.c. The parser subtracts HEADER SIZE, fixed per-frame fields, and FOOTER SIZE from state->target size without first checking the minimum frame length. The wrapped encoded.len value is passed through amqp decode properties() to amqp decode table internal(), where it defeats bounds checks and causes an out-of-bounds read and process crash. An on-path attacker can also trigger the issue when AMQP traffic is not protected by TLS with certificate validation. The demonstrated impact is denial of service, with no reliable memory disclosure or code execution shown. This issue is fixed in version 0.16.0.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BIT-RABBITMQ-C-2026-44235

Produtos afetados

Rabbitmq-C