CyberRota Analysis
AI-GeneratedA vulnerability exists in the channel management of a multiplexing system, where a malicious peer can flood incoming requests, leading to a deadlock of the entire connection. The issue has been addressed by implementing an atomic established state, which ensures that only open confirmation or failure packets are processed before the channel is usable. Organizations utilizing this multiplexing system should prioritize patching to mitigate potential denial-of-service attacks.
Original NVD Description
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.
Related CVEs
Other vulnerabilities affecting the same vendor(s)