Improper input validation in Synapse - CVE-2018-10657
Published: May 2, 2018 / Updated: May 9, 2018
Vulnerability details
The vulnerability exists due to an input validation error where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py. A remote attacker can send malicious messages and perform a denial of service attack.
Note: this vulnerability has been exploited in the wild in April 2018.
Affected software
Ubuntu
Fedora
matrix-synapse (Ubuntu package)
matrix-synapse
How to mitigate CVE-2018-10657
matrix-synapse - update to 0.28.1-1.fc28