Incorrect calculation in Synapse - CVE-2024-31208
Published: April 23, 2024 / Updated: April 23, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper calculation of the auth chain cover index in auth chain indexing when processing specially crafted events from a remote room member. A remote user can send specially crafted events to cause a denial of service.
Exploitation can lead to disk fill and high CPU usage. Servers in private federations, or those that do not federate, are not affected.
Affected software
Fedora
rust-pythonize
matrix-synapse
How to mitigate CVE-2024-31208
rust-pythonize - addressed in versions 0.21.1-1.fc38, 0.21.1-1.fc39, 0.21.1-1.fc40
matrix-synapse - addressed in versions 1.105.1-1.fc38, 1.105.1-1.fc39, 1.105.1-1.fc40