PT-2017-13083 · Open Networking Operating System · Onos

Published

2017-08-30

·

Updated

2022-05-13

·

CVE-2017-13763

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ONOS versions 1.8.0 through 1.10.0
Description The issue is related to the lack of restriction on the amount of memory allocated, specifically due to the unlimited Netty payload size. This can lead to a potential denial of service, as seen in ONOS nodes timing out when attempting to connect to the cluster in a vm test cluster.
Recommendations For ONOS version 1.8.0, consider restricting the Netty payload size to prevent excessive memory allocation. For ONOS version 1.9.0, restrict the Netty payload size to minimize the risk of denial of service. For ONOS version 1.10.0, limit the Netty payload size to prevent potential service disruptions.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-13763
GHSA-C6P7-VHW7-RC9W

Affected Products

Onos