PT-2025-2935 · Unknown+1 · Matrix Media Repo+1
Turt2Live
·
Published
2025-01-16
·
Updated
2025-08-20
·
CVE-2024-52791
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Matrix Media Repo (MMR) versions prior to 1.3.8
Description
The issue arises when Matrix Media Repo (MMR) makes requests to other servers as part of its normal operation, and these servers return large amounts of JSON for parsing. During parsing, MMR can consume large amounts of memory, leading to memory exhaustion.
Recommendations
For versions prior to 1.3.8, upgrade to version 1.3.8 to resolve the issue.
As a temporary workaround for users unable to upgrade, consider configuring forward proxies to block requests to unsafe hosts.
Alternatively, configure MMR processes with memory limits and auto-restart to mitigate the risk.
Running multiple MMR processes concurrently can help ensure a restart does not overly impact users.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matrix Media Repo
Suse