PT-2022-26180 · Synapse+1 · Synapse+1

Kasak

·

Published

2022-03-11

·

Updated

2023-07-06

·

CVE-2022-41952

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Synapse versions prior to 1.53.0
Description The issue arises when Synapse attempts to generate URL previews for media stream URLs without properly limiting connection time. Connections are only terminated after a certain amount of data (max spider size, default 10M) has been downloaded, potentially leading to long-lived connections and excessive traffic towards streaming media servers like Icecast. This can occur if a stream URL is posted to a large room with many Synapse instances that have URL preview enabled. Version 1.52.0 introduces a timeout mechanism to terminate URL preview connections after 30 seconds, and version 1.53.0 further implements an allow list for content types to attempt URL previews.
Recommendations To fully resolve the issue, upgrade to version 1.53.0. As a temporary workaround, turn off URL preview functionality by setting url preview enabled: false in the Synapse configuration file.

Exploit

Fix

Resource Exhaustion

Missing Release of Resource after Effective Lifetime

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1464
CVE-2022-41952
GHSA-4822-JVWX-W47H

Affected Products

Alt Linux
Synapse