Repository navigation
Commit 5e85d2f
Bound the decoded string and bytes payload per lookup
A crafted database can point many data-section pointers at one large
string or bytes value. The value count stays low, but a decoder that
copies each target materializes the value once per pointer, so a file
of a few hundred kilobytes can force gigabytes.
The decoder now charges each string and bytes value its length as it is
decoded and rejects a single lookup that materializes more than 2 MiB,
with an InvalidDatabaseException. Because the charge is made every time
a value is decoded, re-decoding a shared pointer target recharges it, so
the amplification is bounded. Charging before allocation also bounds an
oversized variable-length integer, whose declared size the decoder would
otherwise copy before range-checking. Map keys and inline scalars in a
pointed-to container decode through the same path, so they are charged
too. Metadata is decoded through the same path, so the bound covers the
database-open path as well.
The counter is a per-lookup field on the per-lookup decoder, so
concurrent reads stay thread-safe and the common path stays cheap: small
fixed-width scalars are not charged. This matches the 2 MiB payload limit
used by libmaxminddb and the Go reader. See GHSA-hj94-g986-h9r7.
The test-data submodule is bumped to the MaxMind-DB commit that adds the
payload amplification and boundary fixtures.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>1 parent 872faee commit 5e85d2f
5 files changed
Lines changed: 135 additions & 11 deletions
File tree
- src
- main/java/com/maxmind/db
- test
- java/com/maxmind/db
- resources
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
21 | | - | |
22 | | - | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
23 | 26 | | |
24 | 27 | | |
25 | 28 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
13 | 12 | | |
14 | 13 | | |
15 | 14 | | |
| |||
38 | 37 | | |
39 | 38 | | |
40 | 39 | | |
41 | | - | |
42 | | - | |
43 | | - | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
44 | 47 | | |
45 | 48 | | |
| 49 | + | |
46 | 50 | | |
47 | 51 | | |
| 52 | + | |
48 | 53 | | |
49 | 54 | | |
50 | 55 | | |
| |||
116 | 121 | | |
117 | 122 | | |
118 | 123 | | |
| 124 | + | |
119 | 125 | | |
120 | 126 | | |
121 | 127 | | |
| |||
269 | 275 | | |
270 | 276 | | |
271 | 277 | | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
272 | 296 | | |
273 | 297 | | |
274 | 298 | | |
| |||
445 | 469 | | |
446 | 470 | | |
447 | 471 | | |
448 | | - | |
| 472 | + | |
| 473 | + | |
449 | 474 | | |
450 | 475 | | |
451 | 476 | | |
| |||
493 | 518 | | |
494 | 519 | | |
495 | 520 | | |
496 | | - | |
| 521 | + | |
497 | 522 | | |
498 | 523 | | |
499 | 524 | | |
| |||
1269 | 1294 | | |
1270 | 1295 | | |
1271 | 1296 | | |
1272 | | - | |
| 1297 | + | |
| 1298 | + | |
1273 | 1299 | | |
1274 | 1300 | | |
1275 | 1301 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
571 | 571 | | |
572 | 572 | | |
573 | 573 | | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
| 609 | + | |
| 610 | + | |
| 611 | + | |
| 612 | + | |
| 613 | + | |
| 614 | + | |
| 615 | + | |
| 616 | + | |
| 617 | + | |
| 618 | + | |
| 619 | + | |
| 620 | + | |
| 621 | + | |
| 622 | + | |
| 623 | + | |
| 624 | + | |
574 | 625 | | |
575 | 626 | | |
576 | 627 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2203 | 2203 | | |
2204 | 2204 | | |
2205 | 2205 | | |
| 2206 | + | |
| 2207 | + | |
| 2208 | + | |
| 2209 | + | |
| 2210 | + | |
| 2211 | + | |
| 2212 | + | |
| 2213 | + | |
| 2214 | + | |
| 2215 | + | |
| 2216 | + | |
| 2217 | + | |
| 2218 | + | |
| 2219 | + | |
| 2220 | + | |
| 2221 | + | |
| 2222 | + | |
| 2223 | + | |
| 2224 | + | |
| 2225 | + | |
| 2226 | + | |
| 2227 | + | |
| 2228 | + | |
| 2229 | + | |
| 2230 | + | |
| 2231 | + | |
| 2232 | + | |
| 2233 | + | |
| 2234 | + | |
| 2235 | + | |
| 2236 | + | |
| 2237 | + | |
| 2238 | + | |
| 2239 | + | |
| 2240 | + | |
| 2241 | + | |
| 2242 | + | |
| 2243 | + | |
| 2244 | + | |
| 2245 | + | |
| 2246 | + | |
| 2247 | + | |
| 2248 | + | |
| 2249 | + | |
2206 | 2250 | | |
2207 | 2251 | | |
2208 | 2252 | | |
| |||
Submodule maxmind-db updated 23 files
- .github/workflows/codeql-analysis.yml+3-3
- .github/workflows/links.yml+1-1
- .github/workflows/pages.yml+1-1
- .github/workflows/precious.yml+1-1
- .github/workflows/zizmor.yml+1-1
- MaxMind-DB-spec.md+92
- cmd/write-test-data/main.go+5
- go.mod+3-5
- go.sum+2-2
- pkg/writer/pointerdos.go+418
- pkg/writer/pointerdos_test.go+414
- pkg/writer/rawmmdb.go+5-2
- test-data/MaxMind-DB-test-decoder-payload-limit-over.mmdb
- test-data/MaxMind-DB-test-decoder-payload-limit.mmdb
- test-data/MaxMind-DB-test-decoder-value-limit-over.mmdb
- test-data/MaxMind-DB-test-decoder-value-limit-pointer-heavy.mmdb
- test-data/MaxMind-DB-test-decoder-value-limit.mmdb
- test-data/MaxMind-DB-test-metadata-payload-limit.mmdb
- test-data/MaxMind-DB-test-payload-amplification-dos-string.mmdb
- test-data/MaxMind-DB-test-payload-amplification-dos-worst-case.mmdb
- test-data/MaxMind-DB-test-payload-amplification-dos.mmdb
- test-data/MaxMind-DB-test-pointer-decoder-dos-ipv6.mmdb
- test-data/MaxMind-DB-test-pointer-decoder-dos.mmdb
0 commit comments