PT-2026-105026 · Azure Linux · Librabbitmq
Published
2026-09-17
·
Updated
2026-09-17
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame max value during amqp login(), and rabbitmq-c accepts the value in amqp login inner() in librabbitmq/amqp socket.c. amqp tune connection() in librabbitmq/amqp connection.c uses frame max to reallocate the outbound buffer without enforcing AMQP FRAME MIN SIZE. Immediate serialization of connection.tune-ok through amqp frame to bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Librabbitmq