Lucene search

K
osvGoogleOSV:GHSA-C6P7-VHW7-RC9W
HistoryMay 13, 2022 - 1:43 a.m.

ONOS vulnerable to denial of service due to unrestricted NettyMessagingManager payload

2022-05-1301:43:15
Google
osv.dev
6
onos
vulnerability
nettymessagingmanager
denial of service
memory allocation
version 1.8.0
version 1.9.0
version 1.10.0

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

41.7%

Open Network Operating System, ONOS, versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated because the NettyMessagingManager payload size is not limited. ONOS nodes timeout when trying to connect to the cluster in vm test cluster, leading to a potential denial of service.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

41.7%

Related for OSV:GHSA-C6P7-VHW7-RC9W