Project

General

Profile

Actions

Security #8304

closed
PA PA

dcerpc: internal buffering logic leads to quadratic complexity

Security #8304: dcerpc: internal buffering logic leads to quadratic complexity

Added by Philippe Antoine about 2 months ago. Updated 7 days ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

281f419c0481f7d24d8ce5482b962673a3938e9b

Severity:
HIGH
Disclosure Date:
05/18/2026

Description

Found by oss-fuzz
https://issues.oss-fuzz.com/u/1/issues/485091383
Fixed in 8 and main by #5699

PA Updated by Philippe Antoine about 2 months ago Actions #2

  • Status changed from Assigned to In Review

Gitlab MR

SB Updated by Shivani Bhardwaj about 1 month ago Actions #3

  • Subject changed from dcerpc: internal buffering with split_off(0) leads to quadratic complexity to dcerpc: internal buffering logic leads to quadratic complexity

VJ Updated by Victor Julien 29 days ago Actions #4

  • Severity set to HIGH

Causes high processing cost, leading to reduction of availability. So HIGH.

JI Updated by Jason Ish 28 days ago Actions #5

  • CVE set to 2026-31937

VJ Updated by Victor Julien 27 days ago Actions #6

  • Status changed from In Review to Resolved
  • Git IDs updated (diff)

VJ Updated by Victor Julien 21 days ago Actions #8

  • Status changed from Resolved to Closed

SB Updated by Shivani Bhardwaj 7 days ago Actions #9

  • Private changed from Yes to No
Actions

Also available in: PDF Atom