PT-2025-2935 · Unknown+1 · Matrix Media Repo+1

Turt2Live

·

Published

2025-01-16

·

Updated

2025-08-20

·

CVE-2024-52791

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Matrix Media Repo (MMR) versions prior to 1.3.8
Description The issue arises when Matrix Media Repo (MMR) makes requests to other servers as part of its normal operation, and these servers return large amounts of JSON for parsing. During parsing, MMR can consume large amounts of memory, leading to memory exhaustion.
Recommendations For versions prior to 1.3.8, upgrade to version 1.3.8 to resolve the issue. As a temporary workaround for users unable to upgrade, consider configuring forward proxies to block requests to unsafe hosts. Alternatively, configure MMR processes with memory limits and auto-restart to mitigate the risk. Running multiple MMR processes concurrently can help ensure a restart does not overly impact users.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-52791
GHSA-GP86-Q8HG-FPXJ
GO-2025-3398
OPENSUSE-SU-2025:14704-1
OPENSUSE-SU-2025_0297-1
SUSE-SU-2025:0297-1

Affected Products

Matrix Media Repo
Suse