Validate uncompressed size in OP_COMPRESSED messages - #2976
Open
dfengliu wants to merge 1 commit into
Open
Conversation
The process_compression_header method previously discarded the uncompressed_size field from the compression sub-header. A malicious or compromised server could send a small compressed envelope (passing the max_message_size check) that decompresses to a very large payload, causing memory exhaustion. This change returns the uncompressed_size from the compression header and validates it against max_message_size before accepting the compressed payload.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validate the
uncompressed_sizefield from the OP_COMPRESSED wire protocol compression sub-header againstmax_message_size.Details
The
process_compression_headermethod innetwork_layer.pypreviously unpacked the compression sub-header and discarded theuncompressed_sizefield. A malicious or compromised MongoDB server could send a small compressed envelope (passing the envelope size check) that decompresses to a very large payload, causing memory exhaustion.Changes
process_compression_headernow returnsuncompressed_sizein addition toop_codeandcompressor_iduncompressed_sizeagainstself._max_message_sizeand raisesProtocolErrorif it exceeds the limittest_compression_uncompressed_size_exceeds_max_closes