CVE-2024-53863: Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Impact
In Synapse versions before 1.120.1, enabling the dynamicthumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing.
This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem.
For a list of image formats, as well as decoding libraries and helper programs used, see the Pillow documentation.
Patches
Synapse 1.120.1 addresses the issue by restricting thumbnail generation to images in the following widely used formats: PNG, JPEG, GIF, and WebP.
Workarounds
- Ensure any image codecs and helper programs, such as Ghostscript, are patched against security vulnerabilities. - Uninstall unused image decoder libraries and helper programs, such as Ghostscript, from the system environment that Synapse is running in. - Depending on the installation method, there may be some decoder libraries bundled with Pillow and these cannot be easily uninstalled. - The official Docker container image does not include Ghostscript.
References
- The Pillow documentation includes a list of supported image formats and which libraries or helper programs are used to decode them.
For more information
If you have any questions or comments about this advisory, please email us at security at element.io.
Other sources
Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamicthumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem. Synapse 1.120.1 addresses the issue by restricting thumbnail generation to images in the following widely used formats: PNG, JPEG, GIF, and WebP. This vulnerability is fixed in 1.120.1.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53863?
CVE-2024-53863 has been classified with a moderate severity level due to the potential for exploitation through the processing of uncommon image formats.
How do I fix CVE-2024-53863?
To fix CVE-2024-53863, you should upgrade to matrix-synapse version 1.120.1 or later.
What are the affected versions for CVE-2024-53863?
CVE-2024-53863 affects all versions of matrix-synapse prior to 1.120.1.
What feature triggers the vulnerability in CVE-2024-53863?
The vulnerability in CVE-2024-53863 can be triggered by enabling the `dynamic_thumbnails` option or processing specially crafted requests.
What external tools might be invoked due to CVE-2024-53863?
CVE-2024-53863 could invoke external tools like Ghostscript during the thumbnail generation process for uncommon image formats.