Incorrect calculation in Synapse - CVE-2024-31208

 

Incorrect calculation in Synapse - CVE-2024-31208

Published: April 23, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU127006
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-31208
CWE-ID: CWE-682
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper calculation of the auth chain cover index in auth chain indexing when processing specially crafted events from a remote room member. A remote user can send specially crafted events to cause a denial of service.

Exploitation can lead to disk fill and high CPU usage. Servers in private federations, or those that do not federate, are not affected.


Affected software

Synapse
Fedora
rust-pythonize
matrix-synapse

How to mitigate CVE-2024-31208

Install security update from vendor's website.

Synapse - update to 1.105.1
rust-pythonize - addressed in versions 0.21.1-1.fc38, 0.21.1-1.fc39, 0.21.1-1.fc40
matrix-synapse - addressed in versions 1.105.1-1.fc38, 1.105.1-1.fc39, 1.105.1-1.fc40

External References

Related Security Bulletins