REDHAT-BUG-2466505: High severity Prometheus vulnerability
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Prometheusto a version that resolves this vulnerability.Fixed in 3.5.3 - Upgrade
Upgrade
Prometheusto a version that resolves this vulnerability.Fixed in 3.11.3
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2466505?
The severity of REDHAT-BUG-2466505 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2466505?
To fix REDHAT-BUG-2466505, upgrade Prometheus to versions 3.5.3 or 3.11.3 or later.
What type of vulnerability is REDHAT-BUG-2466505?
REDHAT-BUG-2466505 is a memory allocation vulnerability due to inadequate validation in the remote read endpoint.
Who can exploit REDHAT-BUG-2466505?
An unauthenticated attacker can exploit REDHAT-BUG-2466505 by sending specially crafted snappy-compressed requests.
Which versions of Prometheus are affected by REDHAT-BUG-2466505?
Versions prior to 3.5.3 and 3.11.3 of Prometheus are affected by REDHAT-BUG-2466505.