PT-2017-13083 · Open Networking Operating System · Onos
Published
2017-08-30
·
Updated
2022-05-13
·
CVE-2017-13763
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ONOS versions 1.8.0 through 1.10.0
Description
The issue is related to the lack of restriction on the amount of memory allocated, specifically due to the unlimited Netty payload size. This can lead to a potential denial of service, as seen in ONOS nodes timing out when attempting to connect to the cluster in a vm test cluster.
Recommendations
For ONOS version 1.8.0, consider restricting the Netty payload size to prevent excessive memory allocation.
For ONOS version 1.9.0, restrict the Netty payload size to minimize the risk of denial of service.
For ONOS version 1.10.0, limit the Netty payload size to prevent potential service disruptions.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onos