GHSA-8f34-f56x-9xph: High severity npm/msgpack5 vulnerability
Impact
A truncated map32 header causes an out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError. Applications that rely on IncompleteBufferError to wait for additional bytes may terminate a request, stream, or worker unexpectedly. No adjacent memory is disclosed because the buffer implementation checks bounds.
Patches
The decoder now validates the complete five-byte map32 header before reading its length and reports truncated input as IncompleteBufferError.
Workarounds
Require at least five bytes before decoding a value beginning with 0xdf, or catch RangeError and treat it as incomplete input only for truncated map32 headers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/msgpack5to a version that resolves this vulnerability.Fixed in 6.1.0 - Compensating control
Require at least five bytes before decoding a value beginning with 0xdf to prevent truncated map32 headers from causing an out-of-bounds read.
- Compensating control
Catch RangeError and treat it as incomplete input only for truncated map32 headers.
Event History
Frequently Asked Questions
Which applications are exposed to disruption?
Applications that decode untrusted or incomplete MessagePack input with msgpack5 and depend on IncompleteBufferError to wait for more bytes are exposed. A truncated map32 header can instead raise RangeError, causing a request, stream, or worker to terminate unexpectedly if that error is not handled.
What input is needed to trigger the issue?
An attacker needs to supply truncated MessagePack input beginning with the map32 marker byte 0xdf. The decoder attempts to read the map length before confirming that the full five-byte map32 header is available.
What can be done before patching?
Before decoding a value that begins with 0xdf, require at least five bytes to be available. Alternatively, catch RangeError and treat it as incomplete input only when it results from a truncated map32 header.
Does this expose adjacent memory contents?
No. The out-of-bounds read is checked by the buffer implementation, so it throws RangeError rather than disclosing adjacent memory.